Insights /Active Directory and Group Policy

A domain account keeps locking out: how can you find the computer, mobile device, service, or task using an old password?

Repeated lockouts usually come from an endpoint, service, scheduled task, mapped drive, or mobile device that continues to submit stale credentials.

Quick answer

Repeated lockouts usually come from an endpoint, service, scheduled task, mapped drive, or mobile device that continues to submit stale credentials. For this case, first verify lockout events on the PDC and Caller Computer in event 4740, then use service and scheduled-task credentials to decide whether remediation is needed.

Define the failure boundary first

For this directory and identity case, establish the failure boundary with PDC and 4740 Caller Computer, then continue to service and scheduled-task credentials. Capture the current state, incident time and one known-good comparison before changing production configuration.

Work through the dependency chain

CheckWhy it mattersRecommended action
01 · lockout events on the PDCVerify lockout events on the PDC on the affected path using logs, counters or state information rather than relying only on the configured rule.Record the current value, evidence source and timestamp for lockout events on the PDC. If adjustment is required, change one condition only and retain the original setting for rollback.
02 · Caller Computer in event 4740Verify Caller Computer in event 4740 on the affected path using logs, counters or state information rather than relying only on the configured rule.Check Caller Computer in event 4740 read-only and save the result. If it differs from the baseline, correlate it with the incident time and recent changes before remediation.
03 · service and scheduled-task credentialsVerify service and scheduled-task credentials on the affected path using logs, counters or state information rather than relying only on the configured rule.Compare service and scheduled-task credentials with a known-good peer, the log timeline and the real application path; confirm whether it is causal before changing production.
04 · mapped drives and Credential ManagerReview the current state, related logs and recent changes for mapped drives and Credential Manager, then align them with the incident timeline before deciding whether a change is required.Record the current value, evidence source and timestamp for mapped drives and Credential Manager. If adjustment is required, change one condition only and retain the original setting for rollback.
05 · stale passwords on phones, mail clients and Wi-FiReview the current state, related logs and recent changes for stale passwords on phones, mail clients and Wi-Fi, then align them with the incident timeline before deciding whether a change is required.Check stale passwords on phones, mail clients and Wi-Fi read-only and save the result. If it differs from the baseline, correlate it with the incident time and recent changes before remediation.
06 · multi-DC time alignment and log correlationReview the current state, related logs and recent changes for multi-DC time alignment and log correlation, then align them with the incident timeline before deciding whether a change is required.Compare multi-DC time alignment and log correlation with a known-good peer, the log timeline and the real application path; confirm whether it is causal before changing production.
Read-only examples
Get-WinEvent -FilterHashtable @{LogName="Security";Id=4740} -MaxEvents 20

Change only after the evidence is clear

  1. Start with read-only evidence. Check lockout events on the PDC and Caller Computer in event 4740 before changing configuration.
  2. If the first checks are normal, continue with service and scheduled-task credentials and mapped drives and Credential Manager, keeping evidence tied to the incident time.
  3. Change configuration only when the evidence explains the symptom. For stale passwords on phones, mail clients and Wi-Fi, preserve the original value and define the rollback trigger before adjustment.
  4. Validate multi-DC time alignment and log correlation in a controlled scope before expanding to production users or traffic.

Validation and rollback

  • Validate the complete user or application workflow; do not stop at the single status of lockout events on the PDC.
  • Recheck stale passwords on phones, mail clients and Wi-Fi and multi-DC time alignment and log correlation after the change and confirm that no new bypass, permission expansion or secondary error has appeared.
  • Archive evidence from lockout events on the PDC through multi-DC time alignment and log correlation, together with before/after configuration, business validation and the rollback point.

Common wrong turns

  • Changing PDC and 4740 Caller Computer at the same time, which makes the original cause impossible to prove.
  • Treating a normal result for service and scheduled-task credentials as proof that mapped drives and Credential Manager and the rest of the business path are healthy.
  • Leaving a temporary exception related to stale passwords on phones, mail clients and Wi-Fi or multi-DC time alignment and log correlation in production without an owner, expiry time and rollback note.

Related questions

Where should I start with “A domain account keeps locking out: how can you find the computer, mobile device, service, or task using an old password?”?

Start with lockout events on the PDC and Caller Computer in event 4740; they establish the first useful troubleshooting boundary without changing production state.

What should be checked after the first layer looks normal?

Continue with service and scheduled-task credentials and mapped drives and Credential Manager, then correlate the result with the incident time and the actual user or application path.

What should be retained after the change?

Keep evidence for stale passwords on phones, mail clients and Wi-Fi and multi-DC time alignment and log correlation, plus the original configuration, validation result, observation notes and rollback point.

PreviousA mapped drive is configured through Group Policy but does not appear after sign-in: how should it be troubleshot?NextReplication between primary and additional domain controllers has failed: how should AD, DNS, time, and SYSVOL be checked?

Need an assessment based on your actual environment?