Jul 12, 2006

why a locked out user can still unlock a workstation

This is because unlock process check against only cache hash of password locally. It doesn?t do another logon process with DC. Please see

Account Passwords and Policies : ForceUnlockLogon section

Information About Unlocking a Workstation.

Screensaver Password Works Even If Account Is Locked Out.