On the "Windows Active Dir" platform, when a AD account has a Lockouttime
However the account is not locked in AD - the attribute "Account is locked out" is not ticked. This can occur when the account was previously locked, but the user has not logged into the domain since the unlocking (For example, when AD has unlocked the account automatically via the "Reset account lockout counter after" Group Policy)
Logs show the following for an account that is not locked:
"Reset Password" logs
[DD/MM/YYYY HH:MM:SS] Gathering the change details for managedaccount on dc.yourdomain.com...
[DD/MM/YYYY HH:MM:SS] Checking account managedaccount on yourdomain.com using yourdomain.com\managedaccount...
[DD/MM/YYYY HH:MM:SS] Done
[DD/MM/YYYY HH:MM:SS] Account is locked
[DD/MM/YYYY HH:MM:SS] Invoking LDAP SetPassword for CN=managedaccount,CN=Users,DC=yourdomain,DC=com on 192.168.119.4 using yourdomain.com\managedaccount ...
[DD/MM/YYYY HH:MM:SS] The password for managedaccount on dc.yourdomain.com was successfully changed.
[DD/MM/YYYY HH:MM:SS] Processed the password change for managedaccount on dc.yourdomain.com in 7.383789 seconds"
"Check Password"
Results from the password check follow (all times are Server Time):
[DD/MM/YYYY HH:MM:SS] Gathering the check details for managedaccount on dc.yourdomain.com...
[DD/MM/YYYY HH:MM:SS] Checking the password for managedaccount on dc.yourdomain.com(Windows System) using winad...
[DD/MM/YYYY HH:MM:SS] Checking account object, connecting as yourdomain.com\managedaccount...
[DD/MM/YYYY HH:MM:SS] Done
[DD/MM/YYYY HH:MM:SS] Account is Locked, unable to manage account.
[DD/MM/YYYY HH:MM:SS] Processed the password check for managedaccount on dc.yourdomain.com in 6.9882812 seconds