en-US windows-security computer

Account lockout duration

Verified with Windows Security Options 25H2 — updated on July 25, 2026

Security policy

This is a Security Options policy (Windows Settings > Security Settings), applied by the security engine — not an Administrative Template (ADMX). In GPMC/gpedit it is configured under Local Policies > Security Options.

Path in the GPO console

Computer Configuration\Windows Settings\Security Settings\Account Policies\Account Lockout Policy

Description

This security setting determines the number of minutes a locked-out account remains locked out before automatically becoming unlocked. The available range is from 0 minutes through 99,999 minutes. If you set the account lockout duration to 0, the account will be locked out until an administrator explicitly unlocks it. If an account lockout threshold is defined, the account lockout duration must be greater than or equal to the reset time. Default: None, because this policy setting only has meaning when an Account lockout threshold is specified.

Local security policy

LockoutDuration

This setting has no registry key. It is stored in the local security database (LSA) and is configured through the Group Policy console or secpol.msc.

Embed this policy on your site

What to embed
Theme

Adds one script line: the theme follows your site’s appearance and the height fits the content. If your site blocks scripts, the embed follows the visitor’s system theme.

Preview