I have exchange 2010 setup with multiple CAS/HT servers (multirole) along with a hardware load balancer.
We are facing account lockout issues with one of the mailbox which is used by multiple users.
Recently password has been changed by the user and i think they have used this account to run some third party services which they are not aware or forgot.
As per the security logs of the domain controller, one of the exchange server is causing account lockout issue using IMAP service.
Enabled netlogon logs but can’t find the client system name (null value is observed instead of client system name).
Enabled protocol logging for IMAP but didn’t help, need your expert advice to trace the hostname or the IP address of the client system.