This morning a user was unable to login on his windows account. After unlocking it in the active directory every thing was working again.
Is there a way to see in event viewer or some other place why this account was locked? I read this answer https://serverfault.com/a/391753/76180 but I don't know how to do that.
When you open Group Policy Management you will see a folder under the domain you wish to use labeled Domain Controllers. The policy you need to modify should be the only one under that (by default) called Default Domain Controllers Policy. The specific auditing policy you'll want to enable/modify is Audit account logon events. The audits will show up in the event log under security.