How To Find & Unlock AD User Accounts Using PowerShell

How To Find Unlock AD Users Using PowerShell

This article explains about the various ways to unlock Active Directory user accounts using PowerShell. You can report on and unlock a single account or all accounts. You will either need to be running PowerShell on a domain controller or have the RSAT tools installed on a Windows 10, 11 or management server for this to work.

Find Locked AD User Accounts

Run the Search-ADAccount command with the LockedOut switch in order to report on the AD accounts that are currently locked out in your domian.

Search-ADAccount -LockedOut

Once you have a list of user accounts that are in a locked state, you can either unlock the account of your choice or all of them in one go.

How To Unlock A Single AD Account

Use the command Unlock-ADAccount command with the ‘identity’ parameter to unlock a single account.

Unlock-ADAccount -identity 'username'

You can also use the ‘confirm’ switch to be prompted to check the user details before you unlock the account. The prompt will list the distinguished name of the account which will give you more details.

Unlock-ADAccount -identity 'username' -confirm
Unlock AD User Account using PowerShell 1

Run the command below to confirm that the account has been unlocked.

Get-ADUser cloudiffic -Properties * | Select-Object LockedOut

How To Unlock Multiple AD Accounts

You can use the Search-ADAccount command and pipe it to Unlock-ADAccount if you want to unlock all the accounts in one go.

Search-ADAccount -LockedOut | Unlock-ADAccount
Unlock multiple AD accounts using PowerShell

How To Unlock Only Enabled AD Accounts

You may not want to unlock all locked out accounts, especially if they are disabled as well. Accounts are disabled for a reason and there is no reason to unlock those accounts.

Run the command below if you want to only unlock accounts that are in enabled state.

Search-ADAccount -LockedOut | Where-Object {$_.Enabled -eq $true} | Unlock-ADAccount

Please do let me know if you want help with covering any other scenario to unlock the accounts.

Other Popular Articles


Promote Windows 2025 To Domain Controller

Promote Windows Server 2025 To Domain Controller

Force Ping To Respond With An IPv4 Address

Force Ping To Respond With IPv4 Address

How To Fix GetADGroupMember Size Limit Exceeded Error

Get-ADGroupMember – The size limit for this request was exceeded error

Leave a Comment

Set Microsoft Edge As Default Browser Using Intune

The video below goes through the process of setting up Microsoft Edge as the default browser on a Windows 11 machine using Intune.

Set Microsoft Edge As Default Browser On Windows 11 Using Intune

Getting Started With Entra ID

The video below is aimed at complete beginners who can master the Identity portion of Entra ID in about 90 minutes.

Getting Started With Entra ID - Complete Beginner's Guide

How To Remove Teams Sharing Toolbar While Presenting

The new version of Microsoft Teams bring the ‘annoying’ sharing toolbar in the top middle of the screen while you are presenting in a Teams meeting. There is no way to remove the toolbar which come in between various tabs in a browser or applications that you want to move around.

The video below explains a workaround to remove this sharing toolbar for good while presenting. Hopefully Microsoft will add an option within the app to remove this in the near future.

How To Remove Teams Sharing Toolbar While Presenting