Know where the evidence lives
Event 4625 records a failed logon on the Windows computer handling the attempt, when the relevant auditing is enabled. A workstation's local log is not a complete view of every cloud or domain sign-in. For Microsoft 365 activity, use the tenant's available sign-in logs instead.
Find a short time window
Open Event Viewer, Windows Logs, Security and filter for Event ID 4625. Alternatively, use elevated Windows PowerShell:
Get-WinEvent -FilterHashtable @{
LogName = 'Security'
Id = 4625
StartTime = (Get-Date).AddHours(-24)
} -MaxEvents 50 | Select-Object TimeCreated, Id, MessageThis bounds the displayed results. It is more practical than exporting an entire busy security log to a public troubleshooting site.
Read an event as a set of clues
Check the account under the failed-logon section, not only the subject account. Read Logon Type, source address where present, workstation, status and substatus. Type 2 generally relates to interactive logon, type 3 to network logon and type 10 to remote interactive logon. Missing source details do not automatically mean an event is harmless.
For example, repeated failures from one internal computer immediately after a password change can come from an old scheduled task or saved credential. Repeated attempts against many accounts from an unexpected source call for a different investigation.
Verify the cause
Correlate the time with user activity, scheduled tasks, remote-access logs and the authorised service configuration. Ask the responsible owner before removing a task or changing an account. Preserve the event time and relevant fields. If the pattern suggests compromise, follow the incident process rather than simply deleting the events.
When the query returns nothing
Confirm the computer, time range, privileges and audit settings. An empty result can mean no matching events, rolled-over logs or missing auditing. Do not report it as proof that no failed sign-ins occurred.
Common mistakes
A single failure is often a mistyped password. A high count still needs context. Exported messages can contain usernames, hostnames and addresses, so redact before sharing. Avoid publishing full security logs or disabling auditing to reduce noise.
Official references
Consult the current vendor documentation if your version or screen differs.
Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.