---
name: azion-unlock-a-user-from-account-lockout-policy
description: >-
  Find a user that Account Lockout Policy locked and release the lock with the Azion API before the blocking period ends.
---

# Unlock a user from Account Lockout Policy

**Preview**

An *Account Owner* can release a user that [Account Lockout Policy](/en/documentation/fundamentals/account-lockout-policy/) blocked, through the Azion API. Keep the manual unlock for exceptional or urgent cases. To read the lock records without changing them, refer to [Check Account Lockout Policy logs](/en/documentation/guides/application-security/access-and-compliance/account-lockout-policy-logs/). A user who is locked out and is not an Account Owner can find the options in [Troubleshoot Azion Console sign-in](/en/documentation/support/account-access/).

---

## Prerequisites

- *Account Owner* privileges. A request from any other user returns *Error 403*, and so does a request on an account that does not have the policy activated.
- A personal token for the `Authorization` header. To create one, refer to [Manage personal tokens](/en/documentation/guides/platform/account-and-billing/personal-tokens/).

---

## Find the locked user

Confirm the data of the user in the lock records before you release anyone. The `locked=true` query parameter limits the list to blocked users.

Send a `GET` request to the `identity/users` endpoint:

```bash
curl --request GET \
  --url https://api.azion.com/v4/identity/users?locked=true \
  --header 'Accept: application/json' \
  --header 'Authorization: Token [TOKEN VALUE]'
```

The response is similar to this one:

```json
{
  "count": 2,
  "results": [
    {
      "id": 1,
      ...
      "lockout": {
        "locked_at": "20240101T10:20:01",
        "unlock_at": "20240102T10:20:01",
      }
    }
  ]
}
```

The keys to read in the response:

| Key       | Description                                                                                                                                   |
| --------- | --------------------------------------------------------------------------------------------------------------------------------------------- |
| `count`   | Number of blocked user accounts. Example: `2`                                                                                                 |
| `id`      | Unique identifier of a user                                                                                                                   |
| `lockout` | Period during which the user account stays blocked. `locked_at` is the timestamp the lockout starts, and `unlock_at` is the timestamp it ends |

Save the `id` of the user you want to release.

---

## Release the lock

The request path carries the user `id` from the previous section in place of `{id}`.

Send a `DELETE` request to the `identity/users/{id}/lockout` endpoint:

```bash
curl --request DELETE \
  --url https://api.azion.com/v4/identity/users/{id}/lockout \
  --header 'Accept: application/json' \
  --header 'Authorization: Token [TOKEN VALUE]' \
  --header 'Content-Type: application/json'
```

The response is similar to this one:

```json
{
  "status": "executed"
}
```

The lock is gone, and the user can sign in again.

For every endpoint the API exposes, refer to the [Azion API reference](https://api.azion.com/).

---

## Next steps

- [Configure Account Lockout Policy](/en/documentation/guides/application-security/access-and-compliance/configure-account-lockout-policy.md): Change the attempt limit and the blocking period.
- [Check Account Lockout Policy logs](/en/documentation/guides/application-security/access-and-compliance/account-lockout-policy-logs.md): List the users the policy locked and when each lock ends.
- [Troubleshoot Azion Console sign-in](/en/documentation/support/account-access.md): Regain access when a lock or a lost MFA device blocks you.
- [Account Lockout Policy](/en/documentation/fundamentals/account-lockout-policy.md): Read what the policy locks and the settings that govern it.
