Is there a way to find out the exact reason why user account was locked ? When i run the report it shows the details below so i know where the lock was reported either from user machine or access point or domain controller but it does not tell why the account was locked.
When: |
12/11/2018 11:07:29 AM |
Severity: |
Medium Severity |
Who: |
xxxx\xxxx (xxx, xxx) |
What: |
Account locked for user CN=xxx, xxx,OU=Orange County,OU=Users,OU=xxx,DC=us,DC=xxx,DC=ad. |
Action: |
Modify Attribute |
Result: |
Success |
From: |
1 |
To: |
0 |
Where: |
xxxxxx |
Source: |
Change Auditor |
Origin: |
xxxx.us.xxxx.ad (169.25x.xxx.xxx) |
Facility: |
Custom User Monitoring |
Subsystem: |
Active Directory |
Class: |
user |
Object: |
us.xxx.ad/xxx/Users/Orange County/xxx, xxx |
Attr: |
lockoutTime |
SSL/TLS: |
No |
Sign/Seal: |
No |