AD Users (Locked out) web query displays Active Directory locked out user accounts, located in the domain or OU selected as a scope for the query. Default AD Users (Locked out) web query is included in the built-in Active Directory Admin Unit, and a custom copy of AD Users (Locked out) web query is copied to every new custom Admin Unit.
Active Directory user account gets locked out when exceeding the maximum number of allowed logon attempts, defined in domain locked out policy.
Web queries in a custom Admin Unit are used as a scope for role delegation and attribute policy. When limiting the scope of web queries to a specific OU, you limit the scope of objects available for management to delegated administrators. For more information, please see Administrative Units article.
AD Users (Locked out) query settings
AD Users (Locked out) web query uses common query settings, available for every web query in Active Directory Admin Unit. For the information about common settings, please refer to the following article: