We're using mobile accounts (AD join) with FileVault.
In the last days we got an increasing number of issues with locked mobile accounts and we don't know how to reset this lock.
We see this with 10.14.6 and more with 10.15.5/10.15.6.
The domain account is not locked, it's only the local cached mobile account. If a user wants to authenticate locally (without connectivity to the our corporate network), a message appears with something like "try again in x minutes later". (See screenshot from system preferences as example)
The number of minutes can be 15 min. but will increase, if the user still tries to enter a (wrong) password.
How can we reset this, so the local cached password of a Mobile account can be synced again with the current domain password?