POWERSHELL / ACTIVEDIRECTORY
FreeIntermediateRead-onlylow

Find locked-out AD users

Find currently locked-out Active Directory user accounts with PowerShell and export the account name, UPN and last logon date to CSV.

Generated locally in your browser · Review before running · Opselith does not connect to your tenant

What this PowerShell script does

Finds currently locked-out user accounts

Requirements

    Environment

    • Module: ActiveDirectory
    • Permissions: Directory read access
    • Output: CSV report
    • Context: Windows host with RSAT
    • Risk: Low
    Review before you run The script is generated locally. Test outside production first.
    NEXT STEP

    Ready to generate

    Configure Find locked-out AD users in the Builder, review the generated PowerShell and run it yourself in your own PowerShell session.

    More about this script

    Why use this template?

    Use this free PowerShell script when you need to find currently locked-out user accounts. It is generated locally and can be reviewed before you run it yourself in your own PowerShell session.

    The template uses ActiveDirectory and requires Directory read access. Output: CSV report. Level: Intermediate. Action: Read-only. Risk: Low.

    Review before running

    The script is generated in your browser. Read it before you run it, and test it outside production first. “Read-only” describes the script itself; anything you add around it can still change data.

    Generate the script

    1. Open the template in the PowerShell Builder.
    2. Enter the requested values and review the module, permissions, output and risk.
    3. Generate the script, read it carefully, and test it outside production before use.

    The script is generated locally in your browser. Nothing needs to be uploaded to Opselith.

    Generate Find locked-out AD users →

    How to use this result

    Use this report to list Active Directory user accounts that are currently in a locked-out state.

    When this helps

    • Create a quick lockout report during helpdesk or authentication troubleshooting.
    • Export locked users to CSV when several accounts need follow-up.
    • Confirm whether an account is currently locked before using a separate unlock process.

    How to read the result

    • The template uses Search-ADAccount with LockedOut and UsersOnly, so the result is limited to user accounts reported as currently locked.
    • LastLogonDate is included as context but is not the lockout timestamp and should not be used to determine when the lockout occurred.

    Things to check

    • This script identifies locked accounts; it does not identify the device, service or bad credential that caused repeated authentication failures.
    • The report is read-only and does not unlock accounts. Investigate the cause before using a separate unlock action.

    What to do next: Confirm the user and investigate the lockout source, then use your normal approved process if the account should be unlocked.

    Related tasks

    Official references

    Before you runModule, permissions, inputs, compatibility and script checks
    OPS / SCRIPT DETAILS

    Script details

    Finds currently locked-out user accounts Review these details before generating or running the script.

    securityfinduserspermissions
    Generated here. Run by you.Opselith does not connect to your tenant or run PowerShell. After generating, review the script and run it in your own PowerShell session.

    What it works with

    Module: ActiveDirectory

    ActiveDirectory lets PowerShell work with on-premises Active Directory and is normally installed through Windows RSAT.

    Context: Windows host with RSAT

    Compatibility: Windows PowerShell 5.1 / ISE is supported for this Active Directory template.

    Permissions and changes

    Permissions: Directory read access

    Risk: Low

    Read-only: designed to collect information without intentionally changing the target environment.

    Changes: Read-only. The script reads data and does not intentionally change the target environment.

    Inputs

    • CSV output path - Example: C:\Temp\report.csv (Required)

    What to expect

    Output: CSV report

    Expect a CSV file at the path you choose. Open it in Excel or another CSV viewer and review the rows.

    Example: C:\Temp\report.csv

    This template is in the Free library and is generated locally in your browser. Opselith does not run it; you review and run the script in your own PowerShell session.

    Example use

    Finds currently locked-out user accounts

    Enter the required values in the Builder, review the generated script and confirm the output before running it.

    Before you run: Make sure your account has Directory read access. Check that the ActiveDirectory PowerShell module is available and that you are using the supported PowerShell version. Review the generated script and output path, then test outside production first.
    Script checksWhat has been verifiedQA reviewed
    Static checksPassed
    PSScriptAnalyzerPending
    Real-world run testNot yet recorded
    Last checkedNot yet recorded

    Real-world run results are shown only after Opselith reviews and accepts a tester report.

    Tester: report a result →
    TEST STATUSWhat Opselith has checked

    Last reviewed: 10 Sept 2026

    PSScriptAnalyzer: Awaiting a release PSScriptAnalyzer gate that includes this script. No analyzer pass is claimed yet.

    Pending or Not yet recorded means there is no accepted result on file yet. A passed analyzer check does not mean the script has been run in a real tenant.