Event ID 4740

A user account was locked out

A user account was locked out.

Subject:
    Security ID:        %4
    Account Name:       %5
    Account Domain:     %6
    Logon ID:           %7

Account That Was Locked Out:
    Security ID:        %3
    Account Name:       %1

Additional Information:
    Caller Computer Name:   %2


Event ID 4740 is generated every time a user account is locked out. This account lockout event ID is very helpful when troubleshooting.

For user accounts, this event generates on domain controllers, member servers, and workstations.

Please note Event ID 4767 is generated when an account is unlocked.

ISO 27001:2013 A.9.2.1
NIST 800-171: 3.1.8
NIST SP 800-53: AC-7
CMMC v2 L2: AC.L2-3.1.8


Microsoft Documentation

Event ID - 4740



Name Field Insertion String OS Example
Account Name TargetUserName %1 Any Auditor
Caller Computer Name TargetDomainName %2 Any ComputerName
Security ID TargetSid %3 Any S-1-5-21-3457937927-2839227994-823803824-2104
Security ID SubjectUserSid %4 Any S-1-5-18
Account Name SubjectUserName %5 Any Server1$
Account Domain SubjectDomainName %6 Any Domain
Logon ID SubjectLogonId %7 Any 0x3e7


Lookup Audit Policy Configuration Settings

C:\> AuditPol.exe /get /subcategory:"User Account Management"



LEFT/RIGHT arrow keys for navigation

Back to List