For troubleshooting account lockout issue, excessive administrative privileges are not required. You can create a team or group to troubleshoot this issue by granting only specific rights for reading the essential logs. For that, configure the GPO and apply it to the Domain Controllers OU, as a result your team can access the logs in a single stroke, from multiple DCs and troubleshoot the account lockout issue.
For more details, check out this link, http://support.microsoft.com/default.aspx/kb/323076
Your last visit:x