4767
A user account was unlocked
- Log: Security
- Source: Microsoft-Windows-Security-Auditing
- Account lockouts
- Info
What it means
Someone unlocked a locked-out account. Subject shows who did it.
Why it matters
Confirms helpdesk actions and helps spot accounts that are unlocked again and again.
What to do
- If the same account is unlocked repeatedly, find the lockout source (4740).
Find it with PowerShell
Get-WinEvent -MaxEvents 20 -FilterHashtable @{
LogName = 'Security'; Id = 4767
} | Select-Object TimeCreated, ProviderName, MessageAdd -ComputerName SERVER to query another machine. Other event sources can reuse the same ID number, so check the ProviderName column.
Step-by-step guide
Source
Seeing a lot of these? We can investigate, or alert you automatically through our monitoring.
Talk to us