AD Users (Locked out) web query displays Active Directory locked-out user accounts, located in the domain or OU selected as a scope for the query. Default AD Users (Locked out) web query is included in the built-in Active Directory Admin Unit, and a custom copy of the AD Users (Locked out) web query is copied to every new custom Admin Unit.
Active Directory user account gets locked out when exceeding the maximum number of allowed login attempts, defined in the domain locked-out policy.
Web queries in a custom Admin Unit are used as a scope for role delegation and attribute policy. When limiting the scope of web queries to a specific OU, you limit the scope of objects available for management to delegated administrators. For more information, please see the New Virtual Admin Units article.
AD Users (Locked out) query settings
AD Users (Locked out) web query uses common query settings, available for every web query in Active Directory Admin Unit. For information about common settings, please refer to the following article: