There is a pwpolicy set to disable an account if a password has been entered x number of times incorrectly, and is supposed to reset after a certain amount of time. For some reason i've seen accounts not reset, but stay disabled. I'm able to enable them back again by running "sudo /usr/bin/pwpolicy enable user -u <USERNAME>" or by clearing the policy all together with "clearaccountpolicies". But i'm curious if there is a way to report back to JAMF if a system has any disabled accounts on it. I think it would be helpful to have this so i can see if any local accounts are being locked out and how often it's occurring.
Does anyone know of a way to report on this? All i see in pwpolicy is enableuser and disableuser, but not a "checkuser". Perhaps there is another way?
