The event ids are the specific numbers associated as tags to the specific events in the event log. The account lockout event ids are very helpful in analyzing and investigating the background reasons , users and source involved in the account lockout scenario.
Let us see the account lockout event ids in Windows Server 2003:
Event Id | Event Type | Event Occured | Reason |
---|---|---|---|
529 | Failure Audit | Logon Failure | Unknown user name or bad Password |
539 | Failure Audit | Logon Failure | The user trying to logon is already locked |
612 | Policy Change | Policy Changed | General Audit Policy changed |
643 | Policy Change | Domain Policy Changed | Changes in Account Lockout and Password policis |
644 | Success Audit | User Account Locked Out | The user account has reached the account lockout threshold |
671 | Success Audit | User Account Unlocked | User Account Unlocked |
675 | Failure Audit | Logon Failure | Pre-authentication failed |
Event Id | Event Type | Event Occured | Reason |
---|---|---|---|
4625 | Failure Audit | Logon Failure | Unknown user name or bad Password |
4719 | Policy Change | Policy Changed | General Audit Policy changed |
4739 | Policy Change | Domain Policy Changed | Changes in Account Lockout and Password policis |
4740 | Success Audit | User Account Locked Out | The user account has reached the account lockout threshold |
4767 | Success Audit | User Account Unlocked | User Account Unlocked |
4771 | Failure Audit | Logon Failure | Kerberos Pre-authentication failed |