Collect netmon trace from KDC (Active Directory Server which is configured in KRB5 file in Enforce) while attempting login from Enforce Console. Netmon trace shows lot of timed out event for KRB request. This happens when active directory fails to response kerberos authentication request and retry for any reason, DLP Enforce treat each attempt as failed login attempt and as configured in Enforce user management (configured from passwordenforcement.properties), consecutive failure login for user making that account disable from Enforce, though the account is not locked out from Active Directory.