Paula Wong
asked on
Type of events that get created on Domain Controllers
Does anyone know the event ID(s) that gets created on the domain controller itself if an account is locked out? Event ID 4740 gets created on the actual computer that the user is trying to log on to. Just wondering what Event ID(s) gets created on the domain controller if Event ID 4740 is created on the machine itself. Is Event ID 4740 also created on the domain controller?
Yes, 4740 on the DC as well.
If you would have checked the official documentation, it's explained there.
This event generates every time a user account is locked out.https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4740
For user accounts, this event generates on domain controllers, member servers, and workstations.
ASKER
They are still working on this but the suggestions provided do help to isolate the issue and pinpoint the issue to be elsewhere other than the DC.
ASKER
Known issue.
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.