Issue description
Users encounter the error message "Unable to log you in because your account is locked. Please contact your administrator" when trying to log in to ADSelfService Plus. This error occurs when a user tries to log in with a locked-out Active Directory (AD) account.
Event ID
Event ID 4740 (indicating an account lockout).
Possible causes
- The user has entered incorrect passwords multiple times, resulting in an AD account lockout.
The user's account is being used in other services (e.g., Outlook, mapped network drives, or scheduled tasks) where the password was not updated after a recent password change.
Resolution
Step 1: Use ADSelfService Plus to unlock the account
If the user is enrolled in ADSelfService Plus, they can unlock their account without admin intervention.
Go to the ADSelfService Plus login page.
Click Account Unlock?.
Provide the required identity verification details depending on the configured self-service policy.
Follow the steps to unlock the account.
Step 2: Contact the AD administrator for manual unlock
If the user is not enrolled in ADSelfService Plus, the AD administrator must:
Open Active Directory Users and Computers (ADUC) (dsa.msc).
Locate the locked user account.
Right-click the account and select Properties.
Under the Account tab, check whether Account is locked out is selected.
If locked, uncheck the box and click OK.
Inform the user that the account is now unlocked.
Step 3: Prevent repeated lockouts due to stored credentials
If the user recently changed their password, ensure they update it in:
Outlook (especially if configured with saved credentials).
Mapped network drives.
Scheduled tasks or background services using the old password.
Instruct the user to log out and log back in with the correct credentials.
Validation and confirmation
Tips
How to reach support
If the issue persists, contact our support team here.