Looks right. Maybe you're catching the resultant UserDisable events and not the original? You might drop in the ProviderSID and make sure it's 644/4740 (the "Account Lockout" not "Account Disable" event), or check using a search/filter to see what's causing the rule to fire. When it fires, do you get more than one email?
↧