For a Microsoft Entra Domain Services managed domain, the supported way to trace repeated bad password attempts that lead to account lockout is to use security audits and review event code 4740.
- Enable security audits for Domain Services before the next lockout occurs. Audit events are only captured from the time auditing is enabled.
- Query the audit logs for account lockout events (4740) to identify when lockouts happen.
- Narrow the query to the affected service account to isolate only its lockout events.
- Review the event details for the source. If Source Workstation is blank in 4776 or 4740, the bad password may be coming through a network logon path from another device, such as a RADIUS server forwarding authentication.
Example Kusto queries from the audit logs:
AADDomainServicesAccountManagement
| where TimeGenerated >= ago(7d)
| where OperationName has "4740"
For a specific account, replace the sample account name with the locked service account:
AADDomainServicesAccountLogon
| where TimeGenerated >= ago(7d)
| where OperationName has "4740"
| where "driley" == tolower(extract("Logon Account:\t(.+[0-9A-Za-z])",1,tostring(ResultDescription)))
To review a specific time window:
AADDomainServicesAccountManagement
| where TimeGenerated >= datetime(2020-06-26 09:00) and TimeGenerated <= datetime(2020-07-01)
| where OperationName has "4740"
| sort by TimeGenerated asc
Important details:
- In Microsoft Entra Domain Services, by default, 5 bad password attempts within 2 minutes lock the account.
- The account automatically unlocks after 30 minutes.
- Changing fine-grained password policy does not unlock an account that is already locked.
- Increasing the lockout threshold is not recommended as a first response; trace the source of the bad password attempts first.