Send Knowledge Base Article
The article has been sent to your inbox successfully.
We never share your data
User Account Lockouts and unlocks are missing from reports
This article describes the most common reason of Account Lockouts and Account Unlocks changes missing from reports.
KB1909 | Last review: Mar 25, 2015 | Netwrix Auditor for Active Directory | 5.0 and above
|Symptoms||User Account Lockouts and Unlocks are missing and the corresponding reports are empty, even though some accounts are known to have been locked/unlocked in the selected period.
Daily summary reports also do not show any lockouts or unlocks.
|Cause||The most common reason for this issue is disabled Audit Account Management policy or some conflicts in policies.
Account lockouts, unlocks and Password resets are event-based changes which means that if the audit setting is disabled account lockouts will be detected but will not be included into reports or trigger alerts because there are no corresponding auditing events.
|Resolution||In order to resolve the issue we need to make sure that audit policy is configured correctly.
In the corresponding Group Policy Object (or Local policy if you configured auditing there)
If you use Advanced Audit Policy please check the following setting:
Even if Group Policy Object is configured correctly there might still be some conflicts that prevent GP from applying correctly.
To find out the effective audit policy on a DC, execute the following command
auditpol /get /category:*
In the output check that User Account Management is set to Success
For more information on Group Policy and related issue refer to the following articles:
Was this information helpful?