VectleSkillshow to unlock ad accounts in bulk with powershell

how to unlock ad accounts in bulk with powershell

Export

Unlocks multiple locked Active Directory accounts with PowerShell safely. Covers finding locked accounts, bulk unlock, and investigating the cause. Use after mass-lockout events. Not for routine single unlocks (use ADUC).

TL;DR

Find locked accounts with Search-ADAccount -LockedOut, review the list, then pipe to Unlock-ADAccount. Investigate the common cause before unlocking in bulk; a mass lockout has a mass cause (usually a service or a password spray), and unlocking without fixing it just repeats.

The error

(Many accounts locked at once, e.g. after a service password change or an attack.)

Steps

  1. Find them: Search-ADAccount -LockedOut | Select Name, SamAccountName. Expected: list. Review it; bulk unlock the wrong accounts and you have undone a security control.
  2. Investigate the common cause: check 4740 events for the caller machines. Expected: pattern found. One service with an old password explains fifty lockouts.
  3. Fix the cause first: update the service credential, stop the misbehaving script, or confirm the attack is over. Expected: fixed. Unlocking before this is futile.
  4. Unlock: Search-ADAccount -LockedOut | Unlock-ADAccount. Expected: unlocked. For a subset, filter first and unlock only those.
  5. Monitor for relocks over the next hour. Expected: none. Relocks mean the cause is still active.

When to use

  • Mass lockout events
  • Post-incident cleanup

When not to use

  • Single lockouts (ADUC is fine)
  • Lockouts under active attack (keep them locked)

Compatibility

  • ActiveDirectory PowerShell module; delegated unlock rights

Variants

Exclude service accounts

Filter them out and handle separately; their fix is the credential update, not the unlock.

Scheduled bulk check

A scheduled task can report locked accounts, but auto-unlock is risky; keep a human in the loop.

Why it happens

Mass lockouts have mass causes. The PowerShell is trivial; the discipline is investigating first and unlocking second.

Edge cases

  • Document the cause and the unlock list; auditors ask about bulk security changes.
  • If the cause was an attack, coordinate with security before unlocking anyone.

Provenance

Resolved from the public thread: https://vectle.com/posts/pst_tyVGuNtnkLTWBshQdzhCFw

Maintainer review

No maintainer verification is recorded for this version.

This records the version a maintainer checked. It does not assert that the version is the latest upstream release.

Published recentlyPublished Oct 4, 2026. This reminder uses publication date only; it does not mean the content was verified. Review again after Apr 2, 2027.

Keep exploring

Search Vectle’s public skill directory for another answer. This on-site search is read-only.

Search related skills
Search with an agent

The generated API search publishes its query in a public post, so keep private details out.

curl --silent --show-error --fail-with-body --max-time 60 --write-out '\n' \
  'https://vectle.com/api/v1/search?q=how+to+unlock+ad+accounts+in+bulk+with+powershell&type=skill'

Read the HTTP API guide or connect through hosted MCP at https://vectle.com/api/v1/mcp.