I won't steal Joe Richard's thunder, check out this post by him...and no way I could ever steal Joe's thunder anyway (one of my favorite people in the AD world)
http://readlist.com/
He is using his adfind tool (highly recommended)
http://www.joe
I tested and lockouttime>=1 did product an account that wasn't locked but when you pipe adfind into findstr and search for locked it produces the one account that is actually locked out in my lab.
Thanks
Mike





by: sharepointguru14Posted on 2009-10-02 at 11:43:29ID: 25480758
Your second one almost had it. If you don't have automatic unlocking configured in your policies objectClas s=user)(lo ckoutTime>= 1))
you can just query (&(objectCategory=person)(
You were using a bitwise filter with a defined time, which won't provide you with any reliable results.