Skip to main content

Domain Admin Account LockOut

Summary

This event monitor checks every 15 minutes for a domain admin account lockout. If a lockout is detected, it triggers the CWRMM - Task - Domain Admin Account Lockout task to generate a ticket

Dependencies

CWRMM - Task - Domain Admin Account Lockout

Target

Domain Controllers
This should target the group 'Domain Controllers' as shown below: Target

Monitor Creation

Step 1

Navigate to ENDPOINTSAlertsMonitors
Step1

Step 2

Locate the Create Monitor button on the right-hand side of the screen and click on it.
Step2

This page will appear after clicking on the Create Monitor button:
Step3

Step 3

  • Fill in the mandatory columns on the left side
  • Name: Domain Admin Account LockOut
  • Description: This event monitor checks every 15 minutes for a domain admin account lockout. If a lockout is detected, it triggers the 'Domain Admin Account Lockout' task to generate a ticket.
  • Type: Event
  • Severity: Critical Impact Results
  • Family: Active Directory
    Step3

Step 4

  • Fill in the condition on the right side.

  • Follow the screenshot:
    Step3

  • Click on Add Automation and select Domain Admin Account Lockout task. Step3 Step3

  • Turn Off Ticket Resolution And Select Do not Generate Ticket from the monitor Output DropDown. Step3

Step 5

Click the Select Target button to choose the endpoints for running the monitor set.
Step4

This page will appear after clicking on the Select Target button:
Target

Completed Monitor

CompletedTask