Hi,
A user is locked out per the lockoutstatus.msi tool.
There are no entries in the event viewer security log for event id 4740 on either of my two domain controllers. Also no 4771, 4776, or 529 event ids. My security log goes back years -- it is not the case that the data is archived/overwritten.
I have "Audit Account Management" enabled for success and failure domain-wide via GPO.
How do I determine the source of the lockout?
Thank you,
Chris