Skip to main content
Question

Detecting status of Local account - Is it locked?

  • February 14, 2019
  • 2 replies
  • 11 views

Forum|alt.badge.img+19

I need to detect if a user has locked their account (by typing an incorrect password x times).

Is anyone else reporting on this?

2 replies

Forum|alt.badge.img+19
  • Author
  • Valued Contributor
  • February 25, 2019

<bump>

Anybody?


Forum|alt.badge.img+15
  • Valued Contributor
  • February 25, 2019

Check out this post: https://kevinbecker.org/blog/2015/09/17/unlock-an-active-directory-account-using-mac-os-x-directory-utility

My org doesn't have the lockoutTime attribute, but you might have it. If you do, then you could create an extension attribute that pulls that value. Use grep or awk to narrow down the exact value you need.

/usr/bin/dscl . -read /Users/$userNameHere | grep lockoutTime