Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

For most on-premises Active Directory lockouts, start with the domain controllers’ Security logs and Microsoft’s free Account Lockout and Management Tools. Event ID 4740 confirms the lockout; Events 4625 and 4776 can help trace the failed authentication. Use LockoutStatus.exe to identify involved domain controllers, PowerShell or EventCombMT.exe to search across them, and temporary Netlogon logging when the caller remains unclear. A commercial tool is worth considering when you need centralized history, alerts, or broader audit reporting—not simply because an account locked once.

The right tool depends on where the identity is managed and how the sign-in reaches it. An on-premises AD utility will not necessarily explain an Entra ID sign-in, and a domain controller may see a VPN or RADIUS server rather than the device that supplied the old password.

First identify which identity system is locking the account

“Account lockout” can describe different systems. Before searching logs, establish the username, domain or tenant, approximate time and time zone, and whether the account is a human user, service identity, scheduled-task identity, managed service account, or computer account.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Environment or path Where to begin Important limitation
On-premises AD DS Domain controller Security logs, especially Event 4740; then correlate 4625 and 4776 Caller Computer Name may identify an intermediary, not the original endpoint.
Microsoft Entra Domain Services Domain Services audit data and Log Analytics, if auditing was enabled Do not assume on-premises DC tools or logs cover the managed domain.
Microsoft Entra ID sign-in Entra sign-in and audit records An AD DS lockout tool is not a general Entra ID sign-in analyzer.
AD FS federation AD FS Security events, including Event 411 or, for older versions covered by Microsoft’s guidance, Events 4625 and 501 Federation logs may be needed to reveal a submitting IP or authentication path.
VPN, RADIUS/NPS, Wi-Fi, NAS, or application Follow the path into the VPN, NPS/RADIUS, controller, NAS, or application logs The DC may record only the system that forwarded the authentication.

For a local Windows account, investigate that computer rather than assuming a domain controller is involved. In hybrid environments, determine whether the failed attempt reached on-premises AD DS, Entra ID, Entra Domain Services, or a federation service.

A free, evidence-first troubleshooting workflow

  1. Confirm the symptom. Record the exact account, domain, reported time, time zone, and whether the account is currently locked. Distinguish a lockout from repeated failed sign-ins that have not crossed the configured threshold.
  2. Find Event 4740 on the domain controllers. Record the event time, domain controller that logged it, locked account, and Caller Computer Name if present. Search all relevant DCs, not just the one nearest the user.
  3. Correlate failed-authentication events. Around the same time, examine Event 4625 for failure reason/status, logon type, workstation, source address, process, and authentication package where available. Check Event 4776 for credential validation handled by a DC, particularly in NTLM-related paths. Event 4767 can help show when an account was unlocked.
  4. Use LockoutStatus.exe to orient the search. It helps show lockout information and the domain controllers involved. Treat it as a locator, not a complete root-cause analyzer.
  5. Search centrally if needed. Use EventCombMT.exe, PowerShell, or an existing log platform to query multiple DCs and correlate the time window.
  6. Follow the caller. If the caller is a workstation, inspect its saved credentials, services, tasks, and applications. If it is a VPN, RADIUS/NPS, proxy, or federation server, continue into that system’s logs to find the original client or workload.
  7. Escalate logging only when evidence is insufficient. Temporarily enable Netlogon debug logging on the narrowly selected systems, or use the AD FS-specific procedure when federation is the path.
  8. Fix the source before unlocking. Update or replace the stale credential, stop the repeated attempt, then unlock the account if required. Otherwise, it may immediately lock again.
  9. Turn off diagnostic logging and preserve the evidence. Record the root cause, corrective action, event times, and any relevant log extracts.

What the main events can—and cannot—tell you

  • 4740: Confirms that an account was locked and may provide a caller computer name. It does not guarantee that the name is the original physical device, and it may be blank. Microsoft documents that network authentication forwarded by another device, such as a RADIUS server, can leave the source workstation blank.
  • 4625: A failed logon. The fields can identify logon type, failure status, workstation, source network address, process, or package, but not every field is populated for every protocol and event path.
  • 4776: Credential validation handled by a domain controller. A blank workstation field does not prove that no endpoint exists; the request may have arrived through another system or protocol.
  • 4767: An account-unlocked event useful for distinguishing a single manual unlock from repeated lock/unlock cycles.

Use timestamps carefully: inconsistent time zones or clock skew can make events look unrelated. A missing event may mean the wrong DC or time range, insufficient auditing, log rollover, or that the lockout occurred in a different identity system. No analysis tool can recover an event that was never recorded or has already been overwritten.

Microsoft Account Lockout and Management Tools

Microsoft’s Account Lockout and Management Tools download lists version 1, published July 15, 2024, as ALTools.exe. Microsoft’s tool overview was updated February 12, 2026. The package contains several utilities with different purposes:

Utility Useful for Qualification
LockoutStatus.exe Viewing lockout information and identifying relevant DCs It helps direct the investigation; it does not by itself establish the originating process or device.
EventCombMT.exe Collecting matching event-log entries from multiple computers Requires access to event logs and the relevant auditing to be configured.
NLParse.exe Extracting useful entries from Netlogon logs Useful only after the relevant Netlogon logging has been enabled and captured.
ALockout.dll Helping identify a client-side process or application submitting bad credentials Do not use on Exchange servers or servers hosting network applications. Microsoft warns it can interfere with Exchange Store startup and should not be used on servers running network applications.
AcctInfo.dll Adding account-information pages to Active Directory Users and Computers Provides account and password-age context; it is not a source-tracing tool.
ALoInfo.exe Displaying account names and password ages More useful for inventory and password-age investigation than for finding the submitting device.
EnableKerbLog.vbs Enabling Kerberos logging on clients A legacy-oriented diagnostic component; use only when Kerberos logging is relevant and scope it carefully.

The download page includes legacy system requirements; that is not a recommendation to deploy new systems on obsolete Windows versions. Follow current Windows support guidance and your organization’s software controls.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Search with Event Viewer or PowerShell

In Event Viewer, inspect Windows Logs > Security on the domain controllers. Filter for 4740, then inspect nearby 4625 and 4776 events on the DC and suspected caller. Remote Security-log access requires suitable permissions, and the log must retain the time period you need.

Rank #2
Sale
Mastering Active Directory: Design, deploy, and protect Active Directory Domain Services for Windows Server 2022
  • Mastering Active Directory: Design, deploy, and protect Active Directory Domain Services for Windows Server 2022, 3rd Edition
  • ABIS BOOK
  • Packt Publishing

For a quick query on the current computer, which should be a relevant DC:

Get-WinEvent -FilterHashtable @{
    LogName = 'Security'
    Id      = 4740
} -MaxEvents 50 |
Select-Object TimeCreated, MachineName, Id, Message

To filter that DC’s events to one account:

$User = 'jdoe'

Get-WinEvent -ComputerName DC01 -FilterHashtable @{
    LogName = 'Security'
    Id      = 4740
} |
Where-Object { $_.Message -match [regex]::Escape($User) } |
Select-Object TimeCreated, MachineName, Message

To search a set of domain controllers:

$DCs = 'DC01','DC02','DC03'
$User = 'jdoe'

foreach ($DC in $DCs) {
    Get-WinEvent -ComputerName $DC -FilterHashtable @{
        LogName = 'Security'
        Id      = 4740
    } -ErrorAction SilentlyContinue |
    Where-Object { $_.Message -match [regex]::Escape($User) } |
    Select-Object @{Name='DomainController';Expression={$DC}},
                  TimeCreated,
                  Message
}

These examples use message-text matching for convenience. In production, prefer filtering the event’s XML fields for the account SID or target account rather than relying on localized or formatted message text. Add a bounded time window for large logs, and export results if you need a durable case record, for example by piping selected objects to Export-Csv. PowerShell can automate searches or feed a scheduled alert, but it reports available event data; it cannot reconstruct missing source details. Search every relevant DC because placement and replication timing can make a single-DC query incomplete.

When to enable Netlogon debug logging

If the event trail does not expose enough of the authentication path, Microsoft documents this temporary command for supported Windows client and server versions:

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Nltest /DBFlag:2080FFFF

Netlogon writes to %windir%debugnetlogon.log. If necessary, restart the service to apply the setting:

net stop netlogon
net start netlogon

Reproduce or capture the issue, inspect the log, and then disable verbose logging:

Nltest /DBFlag:0x0

Microsoft also documents a Group Policy setting at Computer Configuration > Administrative Templates > System > Net Logon > Specify log file debug output level. The decimal equivalent of 0x2080FFFF is 545325055. Scope this setting to affected computers; do not broadly apply verbose logging through a policy such as Default Domain Policy.

Netlogon logging is verbose, so keep it enabled for the shortest practical period and monitor disk usage. Microsoft documents a default maximum log size of 20 MB when no other maximum is configured. At the limit, the active log is renamed Netlogon.bak and a new log begins; the limit applies separately to the active and backup files, so total use can be about twice the configured size. See Microsoft’s Netlogon debug logging guidance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

AD FS, Entra Domain Services, and hybrid cases

AD FS

If bad credentials are submitted through AD FS, a domain controller may not reveal the initiating client. Microsoft’s guidance for Windows Server 2012 R2 and 2016 AD FS directs administrators to examine AD FS Security Event 411. The AD FSBadCredsSearch.ps1 script can produce a CSV with the UPN, submitter IP address, and time of bad-credential submissions. For older AD FS versions covered by Microsoft’s procedure, examine Events 4625 and 501 and use ADFSSecAuditParse.ps1. Missing IP details on older systems may relate to required hotfix levels. Follow the version-specific steps in Microsoft’s AD FS account-lockout guidance.

Microsoft Entra Domain Services

Entra Domain Services has its own managed-domain audit path. Microsoft gives five failed password attempts within two minutes as a default example, but effective behavior depends on the configured policy and scope; do not generalize that example to all Active Directory deployments. Audits capture events only after auditing is enabled, so enable the relevant audit collection before the next incident where possible.

Microsoft’s example Log Analytics query filters the account-management table for Event 4740:

AADDomainServicesAccountManagement
| where TimeGenerated >= ago(7d)
| where OperationName has "4740"

A source workstation can be blank when a network authentication was forwarded through another device such as a RADIUS server. Also consider password synchronization: after a password is changed in on-premises AD DS, the new password may take time to synchronize to the managed domain. Attempts made before synchronization completes can contribute to lockout behavior. Changing the lockout policy does not unlock an account that is already locked. See Microsoft’s Entra Domain Services lockout troubleshooting guidance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Common causes to check after locating the path

A lockout tool identifies evidence; remediation usually means finding and updating the system that keeps submitting the wrong secret. After a password change, check:

  • Endpoints and saved credentials: Windows Credential Manager, mapped drives, saved Remote Desktop credentials, logon scripts, disconnected or old virtual machines, and password managers.
  • Phones and tablets: mail clients, VPN clients, Wi-Fi profiles, and devices that were offline during the password change.
  • Background work: Windows services, Scheduled Tasks, IIS application pools, SQL Server agents or jobs, backup software, monitoring agents, and scripts with hard-coded credentials.
  • Shared infrastructure: NAS devices, printers or scanners using SMB or SMTP credentials, and line-of-business applications.
  • Network authentication: VPN, RADIUS/NPS, Wi-Fi controllers, firewalls, and remote-access systems. Follow the chain beyond the server name shown in the DC event.
  • Federation and synchronization: AD FS submission logs and password synchronization timing in Entra Domain Services.

For a service or task, update its credential or migrate it to a group Managed Service Account (gMSA) where appropriate. Prefer a dedicated service identity over a shared human account. Repeatedly unlocking the account without stopping the service or task only starts another cycle.

If lockouts affect many accounts, come from unexpected IP addresses, or occur outside normal usage patterns, treat the activity as a potential password-spraying or other security incident. Review exposed authentication services and application health, preserve logs, and follow incident-response procedures. Do not lower the lockout threshold or disable lockout protection just to suppress the symptom.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Which account-lockout tool should you choose?

Option Best fit Trade-offs and limits
Microsoft utilities, Event Viewer, and PowerShell On-premises AD teams handling one-off investigations or needing a small software footprint Free and flexible, but the workflow is fragmented and depends on permissions, auditing, retention, and administrator expertise.
Netwrix Account Lockout Examiner Teams that want a focused GUI for on-premises AD lockout investigation Netwrix markets it as free and says it processes Windows Security logs without agents. It still depends on correctly configured domain auditing and available logs; it is not a cloud-only Entra or complete compliance solution.
ManageEngine ADAudit Plus Organizations that need lockout analysis alongside broader AD, Entra, server, workstation, alerting, and compliance reporting A broader paid platform to deploy and maintain, not a lightweight necessity for a single lockout. Its pricing page states licensing is based on domain controllers, Entra tenants, file servers, Windows servers, and workstations rather than only user count.
Existing SIEM or central log platform Organizations already collecting the relevant identity and infrastructure logs centrally Can avoid duplicate tooling if it ingests DC Security logs, AD FS, NPS/RADIUS/VPN, endpoint, Entra, and relevant NAS or application data. A platform that lacks the necessary sources cannot infer them.

Netwrix describes Account Lockout Examiner as a free, lockout-focused tool. Its documentation says it processes Windows Security logs without agents; audit configuration and log availability still matter.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

ManageEngine’s ADAudit Plus lockout page describes lockout reporting and analysis within a wider audit product. Its pricing page, checked August 18, 2026, listed annual starting prices of US$595 for Standard and US$945 for Professional, with those examples applying to two domain controllers; one Entra tenant was listed at US$995 annually. Prices, licensing examples, and included features can change, so verify the current terms before buying.

Netwrix Auditor Essentials is a separate, broader product—not a paid version of the focused free Examiner by implication. Its purchase page listed a starting price of US$20 per enabled AD user plus cloud-only Entra ID user as of August 18, 2026, with annual minimum commitments. Consider it only if broader audit coverage matches the need; see Netwrix’s purchase page.

Before selecting any analyzer, verify that it searches all DCs, correlates 4740/4625/4776, distinguishes caller computer from source IP, retains history beyond Windows log retention, exports evidence, and can ingest the relevant AD FS, RADIUS/NPS, VPN, Entra, NAS, and application logs. Also check whether it alerts before or at lockout, distinguishes user from service or machine activity, and requires agents. A product name alone does not guarantee visibility into your authentication topology.

Quick tool-selection guide

Situation Start with Escalate to Buy when Main limitation
Small on-premises AD environment; one recurring lockout Event 4740, LockoutStatus.exe, and nearby 4625/4776 events PowerShell across all DCs; temporary Netlogon logging if needed Only if recurring investigations justify central history or easier help-desk workflows Short event retention and fragmented manual searches
Many DCs; repeatable searches or alerts needed PowerShell or existing central log platform EventCombMT.exe or a SIEM with relevant event sources If reporting, alerting, retention, or broader audits exceed in-house capacity Scripts and central rules still depend on correctly collected data
Help desk wants a focused GUI Netwrix Account Lockout Examiner Microsoft event tools and source-system logs for intermediaries For broader AD or compliance needs, assess a full audit platform Windows log visibility does not automatically include VPN, mobile, or cloud sources
Organization needs broad identity and infrastructure auditing Existing SIEM/log platform, if it already has the sources Evaluate ADAudit Plus or a broader audit suite When centralized reporting, alerting, compliance evidence, and coverage justify deployment Higher scope and operational overhead than a one-off lockout tool
Entra Domain Services or AD FS path That service’s audit/sign-in path and version-specific Microsoft guidance Log Analytics, AD FS scripts, and intermediary logs Only if the product explicitly supports and ingests those sources On-premises AD utilities alone may not expose the original sign-in source

For the majority of on-premises cases, the simplest sound choice is Microsoft’s tools plus event correlation. Add a GUI or paid platform when it solves a defined collection, retention, alerting, or reporting gap.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.