Windows Security Log Event ID 644

Operating Systems Windows Server 2000
Windows 2003 and XP
CategoryAccount Management
Type Success
Corresponding events
in Windows 2008
and Vista

644: User Account Locked Out

On this page

"Target" user account was locked out because of consecutive failed logon attempts exceeded lockout policy of domain - or in the case of local accounts the - local SAM's lockout policy.

In addition to this event Windows also logs an event 642 (User Account Changed)

Free Security Log Resources by Randy

Description Fields in 644

  • Target Account Name: %1
  • Target Account ID: %3
  • Caller Machine Name: %2
  • Caller User Name: %4
  • Caller Domain: %5
  • Caller Logon ID: %6

Supercharger Free Edition

Centrally manage WEC subscriptions.



Examples of 644

User Account Locked Out:
Target Account Name:alicej
Target Account ID:ELMW2\alicej
Caller Machine Name:W3DC
Caller User Name:W2DC$
Caller Domain:ELMW2
Caller Logon ID:(0x0,0x3E7)

Top 10 Windows Security Events to Monitor

Free Tool for Windows Event Collection


Additional Resources