Unlock a user from Account Lockout Policy
Find a user that Account Lockout Policy locked and release the lock with the Azion API before the blocking period ends.
An Account Owner can release a user that Account Lockout Policy blocked, through the Azion API. Keep the manual unlock for exceptional or urgent cases. To read the lock records without changing them, refer to Check Account Lockout Policy logs. A user who is locked out and is not an Account Owner can find the options in Troubleshoot Azion Console sign-in.
Prerequisites
- Account Owner privileges. A request from any other user returns Error 403, and so does a request on an account that does not have the policy activated.
- A personal token for the
Authorizationheader. To create one, refer to Manage personal tokens.
Find the locked user
Confirm the data of the user in the lock records before you release anyone. The locked=true query parameter limits the list to blocked users.
Send a GET request to the identity/users endpoint:
The response is similar to this one:
The keys to read in the response:
| Key | Description |
|---|---|
count | Number of blocked user accounts. Example: 2 |
id | Unique identifier of a user |
lockout | Period during which the user account stays blocked. locked_at is the timestamp the lockout starts, and unlock_at is the timestamp it ends |
Save the id of the user you want to release.
Release the lock
The request path carries the user id from the previous section in place of {id}.
Send a DELETE request to the identity/users/{id}/lockout endpoint:
The response is similar to this one:
The lock is gone, and the user can sign in again.
For every endpoint the API exposes, refer to the Azion API reference.