Solved

Azure domain controller issue

Posted on 2016-08-29
4
35 Views
Last Modified: 2016-09-08
Hi Experts

I have a customer who his admin account is being locked from AD very random. After checking all security logs, more specifically for 4740 events, we can identify the source of the locked accounts appears to be a domain controller in Azure. My client has a hybrid AD-Azure and Office 365- Exchange 2010.



Any ideas on why the 4740 event is logged in a DC in Azure? My client has closed all RDP sessions from the domain, and even the dc in Azure, but his admin account keeps being locked very random, and the source of the locked account is the 2 DCs in Azure



Any ideas on how to resolve this issue?



Please, provide instructions step by step to resolve the issues, and an explanation on why the DC in Azure seems to be the source of the locked account?
0
Comment
Question by:Jerry Seinfield
  • 2
  • 2
4 Comments
 
LVL 6

Accepted Solution

by:
Ganesamoorthy S earned 500 total points
Comment Utility
enable netlogon logs on source Domain Controller in Azure to locate the affending IP

http://www.windowstricks.in/2016/06/account-lockout-caller-computer-name-blank-cisco-workstation-domain-controller.html
0
 

Author Comment

by:Jerry Seinfield
Comment Utility
is this applicable for Windows server 2012 R2 domain controllers in Azure and on Premises?
0
 
LVL 6

Expert Comment

by:Ganesamoorthy S
Comment Utility
Yes, it's applicable for Domain controllers in in Azure and on Premises
0
 

Author Comment

by:Jerry Seinfield
Comment Utility
All good
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

Sometimes drives fill up and we don't know why.  If you don't understand the best way to use the tools available, you may end up being stumped as to why your drive says it's not full when you have no space left!  Here's how you can find out...
Synchronize a new Active Directory domain with an existing Office 365 tenant
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

763 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now