how to unlock a locked active directory account
Unlocks a locked Active Directory user account and finds the lockout source. Covers ADUC unlock, the lockoutStatus attribute, and tracing the bad-password origin with event logs. Use when Windows or Okta (AD-delegated) reports an AD lockout. Not for Okta-native lockouts.
TL;DR
Open Active Directory Users and Computers, find the user, open Properties > Account, and check "Unlock account". Then find the lockout source in the security event log (event 4740 names the caller machine) so it does not relock in ten minutes.
The error
The referenced account is currently locked out and may not be logged on to.Steps
- Open Active Directory Users and Computers (ADUC), find the user, open Properties > Account tab. Expected: "Unlock account" checkbox is checked. Check it and click OK.
- Confirm unlock: the checkbox clears and the account shows as unlocked. Expected: user can sign in immediately.
- Find the lockout source: on a domain controller, open Event Viewer > Security log and filter for event 4740 with the username. Expected: the "Caller Machine Name" field shows the offending device.
- Go to that device and fix the stale credential: saved Wi-Fi password, mapped drive, scheduled task, or phone mail app. Expected: no new 4740 events after the fix.
- If the source cannot be found, use the Microsoft Account Lockout Status tool (lockoutstatus.exe) to check lockout state across all DCs. Expected: all DCs show unlocked after replication.
When to use
- AD account locked (Windows logon, VPN, or Okta with AD delegation)
- Recurring lockouts pointing at one device
When not to use
- Okta-native users with no AD link (unlock in Okta)
- Entra ID-only (cloud) accounts (use Entra admin center)
Compatibility
- Windows Server Active Directory (2016+); RSAT/ADUC on the admin workstation
Variants
Unlock checkbox is grayed out
You lack permission or the account is disabled rather than locked. Check with a domain admin.
Account relocks instantly
The bad-password source is still hammering. Do not unlock again until the source device is found and fixed.
Why it happens
AD locks accounts after the bad-password threshold in the Default Domain Policy. Mobile devices with old Wi-Fi passwords and services with embedded credentials are the classic repeat offenders.
Edge cases
- Read-only domain controllers: unlock on a writable DC; replication to RODCs follows.
- Fine-grained password policies: the threshold may differ per group; check which PSO applies.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_lvmiVr0rKQpCZhsZ7qUKlA
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.