
Active Directory Administration Cookbook, Second Edition
By :

User accounts may get locked out. In this recipe, we will see how to find locked-out accounts.
To find locked-out user accounts, sign in to a domain controller or a member server and/or device with RSAT for Active Directory Domain Services installed.
By default, any user object in Active Directory can be used to find locked-out accounts, as this kind of information is available to the Everyone group.
There are two ways to find locked-out users:
The Active Directory Administrative Center allows for filtering locked-out user objects. Filters can be used on OUs and containers.
To find currently locked-out user objects using the Active Directory Administrative Center, follow these steps: