In Identity I don't seem to be able to see the location of a failed logon due to wrong password. For example, I have used a test account and inputted a wrong password until it has locked out. However, in Identity all I see is 'Account locked out'. There is no alert for failed logon due to bad password and it does not show me the computer account where the failed authentication occurred.
This logical activity was as a result of the AD sync, MDI can see the change in the lock state as it's an attribute in the entity that got changed. make sure to mark all possible logical activities in the profile view, can you see the auth failures there? Do you have full DC coverage with sensors, and all are healthy ?