A lockout is the most common ticket on any service desk, and it is the one most often closed badly. The account is locked, you unlock it, the user gets back in, everybody is happy. Then it locks again at lunchtime, and the ticket comes back with a tired person on the other end of it.
How to work a lockout so it does not come back
- Verify who you are speaking to before you touch anything. This is the step an attacker is counting on you to skip.
- Look at the account and confirm it is genuinely locked rather than disabled or expired. Those three states look identical to the user and need different fixes.
- Unlock it, and only reset the password if it is also expired or genuinely forgotten.
- Read the failed sign in history. Note the source device and how close together the attempts were.
- Ask the user about that device by name. A phone still set up with the old password is the single most common answer, followed by a computer they left signed in somewhere else.
- Have them update or sign out of that device while you are still on the call, then watch for one more failure before you close.
Where repeat lockouts actually come from
- A phone or tablet still collecting company mail with an old password.
- A mapped network drive that reconnects with saved credentials at sign in.
- A saved credential in the Windows credential store, often for a share or a printer.
- A scheduled task or service configured to run as the user.
- A second computer, or a remote session, still signed in with the previous password.
- Somebody genuinely mistyping it, which is worth ruling in rather than assuming.
Write the cause in the closeout, not just the action. A note that says the account was unlocked tells the next technician nothing. A note that says the account was unlocked and a phone still holding the previous password was updated on the call tells them the ticket is finished, and tells them where to look first if it is not.