Skip to main content

User Management - Account Lock Detail

Purpose

The purpose of this document is to outline the user lockout account audit process.

Associated Content

ContentTypeFunction
User Management - Account Lockout AuditScriptCollects the account lockout details
Account LockOut AuditDataviewShows the details of account lockouts
AD Account Lockout DetectionRemote MonitorMonitors to detect lockout accounts
plugin_proval_account_lockTableCollects information about lockout accounts

Implementation

The monitor is required to run every 15 minutes, and the script is required to run as an autofix. The table and Dataview will be updated by the script.

For the AD users' account lock report:
Apply the remote monitor to the DC group.

For all users' account lock report (local users):
Schedule on all Windows machines.