Having a problem where a local user is getting locked out every 15-20 minutes, event id 4740. It shows that it's always coming from the same computer account.
What else can I check to see what's actually locking the account? This is occurring all hours and when no users are in the office.
I've blocked all RDP WAN to local IP traffic but don't know if that's sufficient.