none
Domain Account keeps on locking out RRS feed

  • Question

  • Good day

    My User account keeps on locking out. When I go throught Security Event Logs I get the Caller Computer is MSTSC. I have no computer or server like that on my domain.  Below is the event log:

    Log Name:      Security
    Source:        Microsoft-Windows-Security-Auditing
    Date:          2018/02/08 03:40:07 PM
    Event ID:      4740
    Task Category: User Account Management
    Level:         Information
    Keywords:      Audit Success
    User:          N/A
    Computer:      SERVERDC.Domain.local
    Description:
    A user account was locked out.
    Subject:
     Security ID:  SYSTEM
     Account Name:  SERVERDC$
     Account Domain:  Domain
     Logon ID:  0x3e7
    Account That Was Locked Out:
     Security ID:  Domain\Username
     Account Name:  Username

    Additional Information:
     Caller Computer Name: MSTSC
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />
        <EventID>4740</EventID>
        <Version>0</Version>
        <Level>0</Level>
        <Task>13824</Task>
        <Opcode>0</Opcode>
        <Keywords>0x8020000000000000</Keywords>
        <TimeCreated SystemTime="2018-02-08T13:40:07.387426800Z" />
        <EventRecordID>7600025077</EventRecordID>
        <Correlation />
        <Execution ProcessID="508" ThreadID="6000" />
        <Channel>Security</Channel>
        <Computer>ServerDC.Domain.local</Computer>
        <Security />
      </System>
      <EventData>
        <Data Name="TargetUserName">username</Data>
        <Data Name="TargetDomainName">MSTSC</Data>
        <Data Name="TargetSid">S-1-5-21-329068152-813497703-1957994488-17885</Data>
        <Data Name="SubjectUserSid">S-1-5-18</Data>
        <Data Name="SubjectUserName">SERVERDC$</Data>
        <Data Name="SubjectDomainName">Domain</Data>
        <Data Name="SubjectLogonId">0x3e7</Data>
      </EventData>
    </Event>

    Anyone have seen this before and know how to resolve this??

    Thanks


    enrico

    Thursday, February 8, 2018 2:04 PM

Answers

All replies

  • Try to find that using,

    nslookup MSTSC

    Then you can fing IP and track device..

    Thursday, February 8, 2018 5:11 PM
  • Hi,

    Just checking in to see if the information provided was helpful. Please let us know if you would like further assistance.

    Best Regards,
    William

    Please remember to mark the replies as answers if they help and unmark them if they provide no help.
    If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.

    Monday, February 12, 2018 1:49 AM