← Event ID reference
4740

A user account was locked out

  • Log: Security
  • Source: Microsoft-Windows-Security-Auditing
  • Account lockouts
  • Warning

What it means

An account hit the bad-password threshold and was locked. The Caller Computer Name field shows the device that sent the bad passwords.

Why it matters

Repeated lockouts usually mean a device with an old password; many accounts locking at once can mean an attack.

What to do

  • Query the PDC emulator first; it records most lockouts.
  • Go to the Caller Computer and remove the stale credential.
  • Unlock with Unlock-ADAccount once fixed.

Find it with PowerShell

Get-WinEvent -MaxEvents 20 -FilterHashtable @{
  LogName = 'Security'; Id = 4740
} | Select-Object TimeCreated, ProviderName, Message

Add -ComputerName SERVER to query another machine. Other event sources can reuse the same ID number, so check the ProviderName column.

Step-by-step guide

Find the source of Active Directory account lockouts

Source

Seeing a lot of these? We can investigate, or alert you automatically through our monitoring.

Talk to us