Skip to content
Security

Event ID 4740: Account locked out

A user account was locked outSecurity event 4740 is logged when an account is locked out after too many bad passwords. It names the account and the caller computer that triggered it.
4740
Event ID
4740
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
User accounts
Default logging
Logged by default

What event 4740 means

Event 4740 is written when the account lockout threshold is reached and an account is locked. Domain account lockouts are logged on domain controllers — the PDC emulator is the usual place to find them, since bad password attempts are forwarded to it — while local account lockouts are logged on the machine that owns the account.

The most useful detail is the Caller Computer Name, stored in the TargetDomainName field despite its name: it is the computer from which the failed logons came. It is a NetBIOS name, not an IP address, and it can be empty. The Subject* fields describe the system component that performed the lockout (typically the domain controller's computer account or SYSTEM), not a person.

Lockouts are usually the result of a stale password saved on a phone, mapped drive, service or scheduled task. They are also the visible side effect of password guessing: a single lockout is mostly noise, many lockouts across accounts from one caller is an attack.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Account Management > Audit User Account Management (Success). Enabled for Success in the default Windows audit policy.

Only generated when an account lockout threshold is configured in the password policy. Failed logons against an already locked account show up as 4625 with Status 0xC0000234.

Key fields

FieldWhat it tells you
TargetUserNameAccount that was locked out.
TargetSidSID of the locked account.
TargetDomainNameCaller Computer Name — the NetBIOS name of the computer that sent the failed authentication attempts. Start the investigation there.
SubjectUserNameAccount that performed the lockout, normally the domain controller's computer account (DC01$) or the local system.
SubjectUserSidSID of the subject, typically S-1-5-18 (SYSTEM).

Common benign sources

  • Users who changed their password but still have the old one saved on a phone, laptop, mapped drive or VPN client.
  • Services, scheduled tasks or applications configured with an outdated password, locking the account repeatedly.
  • Users mistyping their password several times.

What attackers do that produces it

  • Password guessing against a single account from one host.
  • Password spraying that overshoots the lockout threshold, causing lockouts of many accounts from the same caller computer.
  • Deliberately locking out administrators or service accounts as a denial of service.

Investigation tips

  • Go to the caller computer and review its 4625 and 4648 events, services and scheduled tasks for the locked account.
  • On domain controllers, correlate with 4771 (Kerberos) or 4776 (NTLM) failures for the account to see the source and failure codes.
  • Count lockouts per caller computer and per time window to separate a misconfigured device from spraying.
  • Check for 4767 (unlock) and 4724 (reset) afterward and for a successful logon by the same account.

MITRE ATT&CK techniques

TechniqueTactics
T1110.001 Brute Force: Password GuessingCredential Access
T1110.003 Brute Force: Password SprayingCredential Access
T1531 Account Access RemovalImpact

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

In-depth guideAccount lockouts and password resets: 4740, 4724 and 4767

Sources and further reading