Link to home
Start Free TrialLog in
Avatar of Paula Wong
Paula WongFlag for United States of America

asked on

Type of events that get created on Domain Controllers

Does anyone know the event ID(s) that gets created on the domain controller itself if an account is locked out? Event ID 4740 gets created on the actual computer that the user is trying to log on to.  Just wondering what Event ID(s) gets created on the domain controller if Event ID 4740 is created on the machine itself. Is Event ID 4740 also created on the domain controller?
Avatar of McKnife
McKnife
Flag of Germany image

Yes, 4740 on the DC as well.
Avatar of Hello There
Hello There

If you would have checked the official documentation, it's explained there.

This event generates every time a user account is locked out.
For user accounts, this event generates on domain controllers, member servers, and workstations.
https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4740
Avatar of Paula Wong

ASKER

They are still working on this but the suggestions provided do help to isolate the issue and pinpoint the issue to be elsewhere other than the DC.
Known issue.
ASKER CERTIFIED SOLUTION
Avatar of Paula Wong
Paula Wong
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial