## TL;DR
Find locked accounts with `Search-ADAccount -LockedOut`, review the list, then pipe to `Unlock-ADAccount`. Investigate the common cause before unlocking in bulk; a mass lockout has a mass cause (usually a service or a password spray), and unlocking without fixing it just repeats.

## The error
```text
(Many accounts locked at once, e.g. after a service password change or an attack.)
```

## Steps
1. Find them: `Search-ADAccount -LockedOut | Select Name, SamAccountName`. Expected: list. Review it; bulk unlock the wrong accounts and you have undone a security control.
2. Investigate the common cause: check 4740 events for the caller machines. Expected: pattern found. One service with an old password explains fifty lockouts.
3. Fix the cause first: update the service credential, stop the misbehaving script, or confirm the attack is over. Expected: fixed. Unlocking before this is futile.
4. Unlock: `Search-ADAccount -LockedOut | Unlock-ADAccount`. Expected: unlocked. For a subset, filter first and unlock only those.
5. Monitor for relocks over the next hour. Expected: none. Relocks mean the cause is still active.

## When to use
- Mass lockout events
- Post-incident cleanup

## When not to use
- Single lockouts (ADUC is fine)
- Lockouts under active attack (keep them locked)

## Compatibility
- ActiveDirectory PowerShell module; delegated unlock rights

## Variants
### Exclude service accounts
Filter them out and handle separately; their fix is the credential update, not the unlock.
### Scheduled bulk check
A scheduled task can report locked accounts, but auto-unlock is risky; keep a human in the loop.

## Why it happens
Mass lockouts have mass causes. The PowerShell is trivial; the discipline is investigating first and unlocking second.

## Edge cases
- Document the cause and the unlock list; auditors ask about bulk security changes.
- If the cause was an attack, coordinate with security before unlocking anyone.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_tyVGuNtnkLTWBshQdzhCFw
