Has anyone dealt with the Teams desktop client repeatedly locking out on-premises Active Directory accounts at random intervals throughout the day? Security auditing points to Teams as the source, but I haven't found a reliable way to stop it. This seems to happen intermittently rather than only after password changes.
4 Answers
It could be an outdated cached credential used by one of the Microsoft 365 desktop components. Logging out of Teams, clearing its cached sign-in data and stored Windows credentials, then signing in again may resolve it.
Don’t rely only on the Teams or cloud logs. Check which domain controller is processing the lockout and review the authentication failure events there, especially events 4771 and 4776. The source workstation and failure reason should point to the actual process. Lockout Status can also show which domain controller has the failure count. If Active Directory shows the failures but the cloud logs do not, Teams may not actually be the source.
Start by clearing the user’s saved credentials from Windows Credential Manager, then sign back in to Teams. Stale credentials are a common cause of repeated lockouts, especially after a password reset.
You can also revoke the user’s active cloud sessions and have them authenticate again. That helps if Teams is repeatedly presenting an old or invalid token.

That has fixed this for us several times. The old password can remain cached even after the user signs in successfully with the new one.