Hello Lysa Analyst,
To trace the source of the bad password, start on the Domain Controller that is processing the lockout and review Security Event ID 4740, which records account lockouts and identifies the Caller Computer Name responsible for the authentication attempt. Also review Event ID 4625 (failed logon) around the same timestamp, as it can provide the source workstation, logon type, and failure details that help pinpoint the system still using the old credentials.
If the account is locking every hour, the most common cause is a scheduled task, service, IIS application pool, mapped drive, or stored credential running under the service account on a forgotten host. Enable auditing if necessary and correlate the lockout time with the source computer reported in Event ID 4740. Microsoft's Account Lockout and Management Tools, particularly LockoutStatus.exe, can help identify which Domain Controller detected the lockout and accelerate the investigation. Once the source host is identified, inspect Task Scheduler, Windows Services, Credential Manager, and any legacy applications for cached credentials, then update or remove the outdated password to stop the recurring lockouts.
If my answer is useful for you, please hit Accept the answer for me please.
HL.