#account-lockout
3 articles
Windows Events3
Windows Event ID 4944 – Microsoft-Windows-Security-Auditing: An account was locked out
Event ID 4944 indicates that a user account has been locked out due to exceeding the maximum number of failed logon attempts within the configured lockout threshold period.
Windows Event ID 4705 – Microsoft-Windows-Security-Auditing: User Account Locked Out
Event ID 4705 indicates a user account has been locked out due to security policy violations, typically from repeated failed authentication attempts or password policy breaches.

Windows Event ID 4740 – Security: User Account Locked Out
Event ID 4740 fires when a user account gets locked out due to failed authentication attempts. Critical for security monitoring and troubleshooting user access issues.