> For the complete documentation index, see [llms.txt](https://docs.oort.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.oort.io/understanding-check-failures/oort-insights/identity-posture-management-insights/user-account-locked-out.md).

# User Account Locked Out

Detects user accounts that are currently locked out. Locked out accounts can indicate repeated failed authentication attempts, password spray activity, or accounts that require administrative review before access is restored.

**Recommended Actions**

Investigate whether the lockout was caused by user error, stale credentials, or suspicious authentication activity. If compromise is suspected, reset or rotate the password before unlocking the account. Review affected systems and cached credentials that may still be attempting to authenticate with old passwords.

**Compatibility**

[Microsoft Active Directory](/integrations/microsoft-active-directory.md)
