Skip to content

Latest commit

 

History

History
35 lines (26 loc) · 1.55 KB

enumerate-locked-out-user-accounts-saved-queries.md

File metadata and controls

35 lines (26 loc) · 1.55 KB
title description ms.date manager audience ms.topic localization_priority ms.reviewer ms.custom
Enumerate locked out user accounts using Saved Queries
provides some step-by-step instructions to enumerate locked out user accounts using Saved Queries
12/26/2023
dcscontentpm
itpro
troubleshooting
medium
kaushika
sap:Windows Security Technologies\Account lockouts, csstroubleshoot

Enumerate locked out user accounts using Saved Queries

This article provides some step-by-step instructions to enumerate locked out user accounts using Saved Queries.

Applies to:   Windows Server 2012 R2
Original KB number:   555131

This article was written by Simon Geary, Microsoft MVP.

More Information

Follow these step-by-step instructions to list all currently locked out accounts in a domain:

  1. Sign in to a Domain Controller with administrative privileges in the domain, and open Active Directory Users & Computers.

  2. Right-click Saved Queries and select New > Query.

  3. Give the query a name and optionally a description. Select Define Query.

  4. Select Custom Search from the drop-down dialogue box.

  5. Select Advanced and enter this LDAP filter in the query box:

    (&(objectCategory=Person)(objectClass=User)(lockoutTime>=1))

  6. Select OK twice and the new query appears under the Saved Queries folder in Active Directory Users & Computers.

[!INCLUDE Community Solutions Content Disclaimer]