asked on
ASKER
Active Directory (AD) is a Microsoft brand for identity-related capabilities. In the on-premises world, Windows Server AD provides a set of identity capabilities and services, and is hugely popular (88% of Fortune 1000 and 95% of enterprises use AD). This topic includes all things Active Directory including DNS, Group Policy, DFS, troubleshooting, ADFS, and all other topics under the Microsoft AD and identity umbrella.
TRUSTED BY
I would enable auditing and interrogate the DCs for this information. See the enable auditing section in this article
https://www.experts-exchange.com/articles/29305/Active-Directory-Locked-Account-Investigation-Process.html
You can use Powershell to enumerate through all the DCs
Here is an example of such a script
Open in new window
https://gallery.technet.microsoft.com/scriptcenter/Get-All-AD-Users-Logon-9e721a89