Active Directory Users Account Lock Problem

Hello,
So many users in Active Directory are locked some how.
When I select one user or a lot of users at once and then when I right click and select unlock, the lock situation is not changing. If I get into properties of one user and in account tab if I check "Unlock Account" problem is being solved.
So to unlock users with this method would take much time and effort.
Is there any way to tackle this trouble?
Thank You
certuranAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

David SankovskySenior SysAdminCommented:
If all the users are part of a specific OU,  you can use PowerShell to unlock them:
GET-ADUSER –filter * –searchbase ‘OU=*SUBOU*,OU=*ParentOU*,DC=*DCNAME*,DC=*DNSSUFFIX*’ | UNLOCK-ADACCOUNT
0
Steven CarnahanNetwork ManagerCommented:
Courtesy of VB ITS's solution: http://www.experts-exchange.com/Networking/Windows_Networking/Q_28562010.html

Import-Module ActiveDirectory
Search-ADAccount –SearchBase ‘OU=India,DC=XYZ,DC=com’ –LockedOut | Unlock-ADAccount

Open in new window


Adjust with your domain information.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Will SzymkowskiSenior Solution ArchitectCommented:
In order to find out exactly where your account is locking out on you need to configure active directory auditing on Default Domain Controllers Policy. Once you have this enabled you will be able to reference the Security Logs on the Domain Controllers and this will provide info on where the accounts are locking out.

 Configure Active Directory Auditing (HowTo on my site)
http://www.wsit.ca/how-tos/active-directory/configure-active-directory-auditing/

 If you have several domain controllers this will be difficult to manage as the logs will be on the domain controller that the user account is authenticating to.

 A great product to accomplish this is Active Directory Auditor by Lepide Software.
http://www.lepide.com/lepideauditor/active-directory.html

 This software will outline in a detailed report exactly where the machine is locking out on.

 Will.
1
Ultimate Tool Kit for Technology Solution Provider

Broken down into practical pointers and step-by-step instructions, the IT Service Excellence Tool Kit delivers expert advice for technology solution providers. Get your free copy now.

chanderpal singh rathoreMicrosoft Exchange EngineerCommented:
Hi,

Please use the below URL to modify your all user's property at one go:

Link: http://careexchange.in/how-to-remove-or-replace-or-add-a-entry-in-a-attribute-in-bulk-using-admodify-tool/

Here you don't have to do this manually for your all users.


Good Luck!!!!!!!!!!!!!
0
compdigit44Commented:
Everyone has posted suggestion on how to unlock account in bulk but did you find the root cause of why they were all locked out???
0
certuranAuthor Commented:
I used combination of suggetions. Thank you
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Active Directory

From novice to tech pro — start learning today.