Hi Experts,
I have AD account on which I have to perform my daily tasks such as login into the remote desktop, scheduler and other tasks.
From past 10 days, my account gets locked daily in the evening around 5:45 to 6:00 PM and daily I have to unlock it which is painful activity.
For troubleshooting purpose I have referred https://activedirectorypro.com/account-lockout-tool/ and performed and RND but unable to understand the real issue.
First I have check that the Orig Lock (Using Lockout Status tool) is one of my domain so I just check event id on that domain controller for event 4740 and caller Computer name is "CSAPL-NMS" so next I log on the caller computer name and
filter event 4625 but unable to find any relevant event to find more description of service on which caller computer is performed.
During review log on caller computer name "CSAPL-NMS" i have found event id 4648 and found that one of Windows Server 2003 name as "cs-new-hrms" is target server.
All the relevant screenshots and logs.
https://crescentpk-my.sharepoint.com/:f:/g/personal/osama_mansoor_crescent_com_pk/EtZfe2oWyF9BqRxgQGzAXfIB_qs5IT83i98u26SZ3eyzzQ?e=c9sc03