## TL;DR
Open Active Directory Users and Computers, find the user, open Properties > Account, and check "Unlock account". Then find the lockout source in the security event log (event 4740 names the caller machine) so it does not relock in ten minutes.

## The error
```text
The referenced account is currently locked out and may not be logged on to.
```

## Steps
1. Open Active Directory Users and Computers (ADUC), find the user, open Properties > Account tab. Expected: "Unlock account" checkbox is checked. Check it and click OK.
2. Confirm unlock: the checkbox clears and the account shows as unlocked. Expected: user can sign in immediately.
3. Find the lockout source: on a domain controller, open Event Viewer > Security log and filter for event 4740 with the username. Expected: the "Caller Machine Name" field shows the offending device.
4. Go to that device and fix the stale credential: saved Wi-Fi password, mapped drive, scheduled task, or phone mail app. Expected: no new 4740 events after the fix.
5. If the source cannot be found, use the Microsoft Account Lockout Status tool (lockoutstatus.exe) to check lockout state across all DCs. Expected: all DCs show unlocked after replication.

## When to use
- AD account locked (Windows logon, VPN, or Okta with AD delegation)
- Recurring lockouts pointing at one device

## When not to use
- Okta-native users with no AD link (unlock in Okta)
- Entra ID-only (cloud) accounts (use Entra admin center)

## Compatibility
- Windows Server Active Directory (2016+); RSAT/ADUC on the admin workstation

## Variants
### Unlock checkbox is grayed out
You lack permission or the account is disabled rather than locked. Check with a domain admin.
### Account relocks instantly
The bad-password source is still hammering. Do not unlock again until the source device is found and fixed.

## Why it happens
AD locks accounts after the bad-password threshold in the Default Domain Policy. Mobile devices with old Wi-Fi passwords and services with embedded credentials are the classic repeat offenders.

## Edge cases
- Read-only domain controllers: unlock on a writable DC; replication to RODCs follows.
- Fine-grained password policies: the threshold may differ per group; check which PSO applies.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_lvmiVr0rKQpCZhsZ7qUKlA
