How to trace bad password attempts ???

Sofie Meier 0 Reputation points
2026-09-17T10:19:26.2333333+00:00

Hi guys

A critical automated service account has been locked out, causing the nightly data processing job to fail. The job runs under a domain account, and repeated bad password attempts seem to be triggering the lockout. Someone explain how to trace the source of these failed password calls ? Many thanks

Windows for business | Windows 365 Business
0 comments No comments

3 answers

Sort by: Oldest
  1. AI answer

    2026-09-17T10:19:44.0033333+00:00

    For a Microsoft Entra Domain Services managed domain, the supported way to trace repeated bad password attempts that lead to account lockout is to use security audits and review event code 4740.

    1. Enable security audits for Domain Services before the next lockout occurs. Audit events are only captured from the time auditing is enabled.
    2. Query the audit logs for account lockout events (4740) to identify when lockouts happen.
    3. Narrow the query to the affected service account to isolate only its lockout events.
    4. Review the event details for the source. If Source Workstation is blank in 4776 or 4740, the bad password may be coming through a network logon path from another device, such as a RADIUS server forwarding authentication.

    Example Kusto queries from the audit logs:

    AADDomainServicesAccountManagement
    | where TimeGenerated >= ago(7d)
    | where OperationName has "4740"
    

    For a specific account, replace the sample account name with the locked service account:

    AADDomainServicesAccountLogon
    | where TimeGenerated >= ago(7d)
    | where OperationName has "4740"
    | where "driley" == tolower(extract("Logon Account:\t(.+[0-9A-Za-z])",1,tostring(ResultDescription)))
    

    To review a specific time window:

    AADDomainServicesAccountManagement
    | where TimeGenerated >= datetime(2020-06-26 09:00) and TimeGenerated <= datetime(2020-07-01)
    | where OperationName has "4740"
    | sort by TimeGenerated asc
    

    Important details:

    • In Microsoft Entra Domain Services, by default, 5 bad password attempts within 2 minutes lock the account.
    • The account automatically unlocks after 30 minutes.
    • Changing fine-grained password policy does not unlock an account that is already locked.
    • Increasing the lockout threshold is not recommended as a first response; trace the source of the bad password attempts first.

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

  2. HLBui 13,020 Reputation points Independent Advisor
    2026-09-17T11:21:13.34+00:00

    Hi Sofie

    The usual way to track down the source of bad password attempts is to dig into the Security Event Logs on your domain controllers. Look for Event ID 4740 (account lockout) and check the “Caller Computer Name” field that tells you which machine is sending the bad credentials. From there, you can pivot to that system and check scheduled tasks, services, or apps that might be running under the account with an outdated password. Another handy tool is Netlogon Debug Logging, which can give you more granular info about authentication attempts. If you want a quicker overview, Microsoft’s Account Lockout and Management Tools bundle can help trace the source automatically. Once you identify the culprit, update the stored credentials or switch the service to a managed account so you don’t hit this again.

    If this helps you where those bad password calls are coming from, please hit “accept answer” so we know it was useful!

    Was this answer helpful?

    0 comments No comments

  3. HLBui 13,020 Reputation points Independent Advisor
    2026-09-21T07:20:43.35+00:00

    If everything is okay, don't forget to share your experience with the issue by "Accept answer". If you need more information, feel free to leave a message. We are happy to help!

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.