When a user's account becomes Locked due to exceeding the login failure limit, an Owner / Team Administrator can unlock it immediately on the spot. While the account is locked, the user cannot log in, but you can enable login immediately without waiting for automatic unlock (default: 15 minutes).
Conditions for account lockout
- When login fails consecutively, the account is temporarily locked
- While locked, the user cannot log in even with the correct password (a message such as "Your account is locked" appears on the screen)
- The account automatically unlocks after a period of time (default: 15 minutes)
You can check the lockout threshold and automatic unlock duration in Password policy.
Unlocking a locked user account
If you need to let someone log in right away, an administrator can manually unlock the account.
- Open User management from the sidebar
- Click the target user to open the details drawer
- Confirm that a red Locked tag appears at the top of the details drawer
- If no tag is shown, the user is not currently locked (including auto-unlocked accounts)
- Select Unlock account from the […] menu in the top right
- Confirm the target user name in the confirmation modal and click Unlink
After unlocking, the login failure count is reset and the user can log in immediately. The Locked tag automatically disappears.
Audit log record
The unlock operation is recorded in the audit log as an accountUnlock event. Since it records who unlocked which user and when, you can operate securely from an internal control perspective. When an account is automatically unlocked after 15 minutes, it is also recorded as an accountUnlock event.
Frequently asked questions
Q. Who can unlock accounts?
A. Only Owner / Team Administrator can perform this. Group Administrator and below will not see the Unlock account menu.
Q. Is the password reset too?
A. No. Only the login failure count is reset. The password itself is not changed. If the user forgot their password and is likely to fail again after unlock, either send a password reset or reissue an initial password (for Email-free accounts).
Q. Can the target user unlock themselves by resetting their password?
A. Resetting the password via the password reset email also effectively resets the failure count (if they log in correctly with the new password, normal operation resumes). However, Email-free account users cannot reset on their own, so administrator unlock or reissuing an initial password is necessary.
Q. How many failures trigger a lock?
A. This is configurable in the team's Password policy. For the default value, see Password policy.