An account locks again minutes after a password reset. What would you check?

Instruction: Explain how you would identify the source of repeated failures, contain the disruption within your authority, and verify recovery without collecting passwords or erasing evidence.

Context:

A Windows 11 user with an on-premises Active Directory account changed their password through the approved process at 08:45. Their account locked at 08:50 and again after an authorized unlock. They also use a second workstation and a scheduled reporting task. You can perform approved help desk checks; the identity team can review domain-controller authentication events.

Updated

Official answer available

Read the opening below, then unlock the full answer and practical guidance.

I'd first verify the caller through the support process and confirm the timing without asking for either password. I'd explain that repeated unlocks are giving only temporary relief, so we need to identify what is making unsuccessful attempts. I'd record the affected account and devices in the restricted ticket, with the user describing which applications were active at each lockout...

Related Questions