Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

New quiz

Total questions: 119

Worksheet time: 1hrs 29mins

Name
Class
Date
1.

What actions can be taken on a Suspended user?

a)

Deactivate

b)

Assign Application

c)

Delete & Reset Multifactor

d)

Activate

e)

Reset Behavior Profile

2.

Users can be unassigned from an app in the following ways:

a)

The organizational unit (OU) that contains the user has been deselected.

b)

The user is removed from a group that is assigned to the app.

c)

The user no longer appears in imports after being deactivated in the app.

d)

The user is deactivated in OKTA.

3.

This advanced option allows user to see the plugin logs in developer console

a)

Reset OKTA plugin

b)

Enable OKTA plugin logs

c)

Enable OKTA Browser logs

d)

Use local Javascript

4.

Which of the following statements are true ?

a)

It is not possible to import AD user that has no first and last names

b)

It is possible to create an OKTA mastered user that has no first and last name

c)

It is not possible to create an OKTA mastered user that has no first and last names

d)

It is possible to import AD user with no first and last names provided both AD and OKTA mastered user profiles have first and last names marked as optional

5.

The following configurations can be set in the Provisioning Settings from OKTA to AD

a)

Enable Password Sync

b)

Provide an email address for activation emails

c)

Configure AD username format

d)

Create User account

e)

Deactivate User account &

Update user attributes in AD whenever OKTA user profile is changed (for an OKTA mastered user)

6.

Global Notifications can be set by these types of administrators

a)

Super Admins

b)

API Access Management Admin

c)

Org Admins

d)

Group Membership Admin

e)

App admins

7.

All websites that are granted access to your OKTA organization thru API must be configured here

a)

Authorization Servers Claims

b)

API token

c)

Trusted origin

d)

Authorization servers Scopes

8.

OKTA supports these methods for provisioning

a)

SCIM standard

b)

WS-Fed

c)

OAUTH 2.0

d)

Template Plugin App

e)

SWA

9.

The default recovery method in password policies and AD delegated authentication is

a)

Email

b)

SMS

c)

Security Question

d)

Voice call

10.

What is the maximum validity period that can be configured for Reset\Unlock recovery emails?

a)

15 days

b)

1 week

c)

1 month

d)

180 days

e)

90 days

11.

Administrator can set Device Trust in a Password Policy

a)

FALSE

b)

TRUE

12.

Password Age can be configured for the following types of users

a)

Both OKTA and Active Directory mastered users

b)

Some options of Password Age can be configured for AD mastered users

c)

OKTA Mastered users only

d)

AD mastered users only

13.

What is the Default format of Username in OKTA?

a)

First name

b)

Email address

c)

Display name

d)

Last name

14.

You can create an OKTA user account (user profile) by

a)

Importing data using CSV file

b)

Adding a Person manually in OKTA application

c)

Importing data through API

d)

Importing from external application or directory

15.

Administrators can set Security Answer Length in the Password Policy

a)

FALSE

b)

TRUE

16.

What are the options available for the administrator when trying to expire password for a user?

a)

Create a temporary password

b)

Send Reset Password Link

c)

Send activation email to user

d)

Send a temporary password to the user

17.

Which actions can an administrator NOT do from the Dashboard?

a)

Add Groups

b)

Add an Admin role

c)

Add Application

d)

Run Reports

e)

Unlock People & Deactivate Users


18.

Who CANNOT remove users from groups?

a)

App Admin

b)

Org Admin

c)

Mobile Admin

d)

API Access Management Admin

e)

Group Admin

19.

Dashboard tabs can be managed by these administrators

a)

Application admins

b)

Super Admins

c)

Mobile Admins

d)

Org Admins

20.

What are the few custom template apps available in OKTA?

a)

Template WS-Fed app

b)

Template Basic Auth app

c)

Template Plugin app

d)

Template Basic App

21.

OKTA's SWA can be used for applications that cannot be setup using SAML or WS-Fed

a)

TRUE

b)

FALSE

22.

The following statements apply to the Groups in OKTA

a)

A provisioning group should be created in order to provision users to Active directory

b)

Group priorities can be set when a single user is part of multiple groups that are assigned to an application

c)

Security policies can be assigned to groups

d)

Groups can be created natively in OKTA or pushed to directory or applications that support groups

23.

Factor Sequencing supports below factors as primary method of authentication

a)

SMS

b)

OKTA Verify

c)

Voice Call

d)

Security Question

e)

Password

24.

Which one is a true statement about Group Rules?

a)

Groups automate provisioning to applications

b)

Require attributes to come from OKTA user profile

c)

Only super admins and org admins can edit rules.

d)

Group rules can be used to assign users to admin groups.

e)

You can only use string attributes in basic condition group rules.

&

Only group admins who manage all groups can search for and view rules.

25.

What is true about OKTA Verify MFA?

a)

OKTA Verify can be used either with Push notification or by entering a verification code

b)

If user loses the device in which OKTA Verify is setup, OKTA Verify can be reset only by Administrator or IT

c)

OKTA Verify is a strong MFA factor and is recommended to setup as a required factor

d)

User will be able to setup OKTA Verify on multiple devices

e)

Multiple accounts can be configured in OKTA verify as long as they belong to different orgs

&

Users will be able to reset MFA factor as long as they can login to their account and a device

26.

Administrators will be able to exclude users from a Password Policy

a)

FALSE

b)

TRUE

27.

Import Safeguard feature gives OKTA an ability to

a)

Define threshold for org wide unassignments

b)

Halt import that cause mass app unassignments

c)

Filter users and groups during import

d)

Prevent accidental loss of user accounts

e)

Define threshold for app unassignments

28.

Which OKTA feature can you use to add custom attributes to your OKTA user profile?

a)

Profile Master

b)

Profile Editor

c)

Profile Mapping

d)

Active Directory groups

29.

Following are true when a rule-managed user is manually removed from a group

a)

User loses access to applications managed by group rule

b)

User cannot be assigned to any application

c)

User cannot be added to any group

d)

User is automatically added to the rule's, Except The following users field.

30.

Name some of the social identity providers

a)

Box

b)

Facebook

c)

LinkedIn

d)

Google

31.

An OKTA Service Account can be created by

a)

OKTA Provisioning

b)

OKTA AD Agent

c)

OKTA Application Integration Wizard

d)

OKTA OPP agent

32.

An Application specific Factor Enrollment policy can restrict user not to enroll in a certain policy

a)

TRUE

b)

FALSE

33.

Authorization server configured in OKTA can act as an OpenID Connect ID provider

a)

TRUE

b)

FALSE

34.

Which provisioning option does not support JIT enabled AD instances?

a)

Licenses\Roles Management Only

b)

Profile Sync

c)

User Sync

d)

Universal Sync

35.

Is this a capability of OKTA Browser Plugin?

a)

When end users are on a password-update page of an OKTA-enabled SWA app, the pop-up banner can automatically insert their current password.

b)

Automatically sign in to apps provided this feature is set in the application

c)

Automatically initiate sign into OKTA

d)

For OKTA admins, an Admin link is available in the Your Apps dialog when sign in to OKTA

e)

Switch between OKTA accounts provided you have previously trusted the account

36.

Select all that is true for Lock Out settings

a)

Show lockout failures is Early Access feature

b)

Minimum setting is 1 minute and maximum is 999 mts for an account to be unlocked

c)

Users have an option to unlock themselves either in OKTA only or OKTA and AD

d)

Automatic unlock of Account is not set by default

&

Maximum number of invalid login attempts before a user gets locked out is 100

e)

For AD mastered users, Maximum failed sign in limit in OKTA has to be set lower than that of AD to prevent AD lock out

37.

What options are available for an administrator when a user is pending action?

a)

Delete the user

b)

Reset multifactor

c)

Resend activation email

d)

Set password and activate

38.

What is true about Single Logout feature?

a)

Allows logout from application and OKTA at the same time

b)

SWA, SAML and OIDC support this feature

c)

Configured for SP initiated flow only

d)

Requires a digital signature for SLO request

39.

A Provisioning error similar to this Automatic provisioning of user John Doe to app Salesforce.com failed: Matching user not found is seen because

· ​

a)

Application is trying to provision into OKTA and did not find matching user

b)

OKTA is trying to provision a user in target application and is not able to find the partial match on first or last names

c)

OKTA is trying to provision a user in target application but Create user is not enabled in Provisioning settings of the application

d)

OKTA is trying to provision user but user with exact match on username is not found

40.

Is this an action that can be performed on an application?

a)

Suspend

b)

Activate

&

Assign to users and groups

c)

Delete

d)

Deactivate

e)

Refresh application data

41.

When an Administrator sets username and password for an application

a)

Credentials are not exposed to end user

b)

Password reveal feature is unavailable to the users

c)

Password is visible to admin only when its created

d)

If the chosen app was previously assigned to an established OKTA group, group members will require manual updates of usernames and passwords for each user.

42.

What is true about Network Zones?

a)

LegacyIPZone is created by default and cannot be deleted

b)

OKTA verifies user's IP from the IP zone if configured in Sign on Policy and decides on access to OKTA Org

c)

Network zones can be IP or Dynamic zones

d)

Blacklisted Ips can be configured to prevent access from certain IP addresses

43.

Can you retry the tasks that failed with the error "Insufficient licensing"?

a)

No

b)

Yes

44.

Is this a feature for a group to access app outside OKTA using OKTA Browser Plugin?

a)

No option available

b)

Enable OKTA toolbar for group

c)

Add a group to OKTA quick access

d)

Enable a group for OKTA Browser plugin app access

45.

Are GA (Generally Available) features added to the orgs automatically?

a)

Administrators have to explicitly enable GA features

b)

GA features are enabled for all eligible orgs automatically

c)

No, OKTA support have to enable them explicitly

d)

GA features are enabled for all eligible orgs automatically except some may have to go through a release process before getting released to all orgs immediately after release

46.

When an Identity Provider authentication is used, IdP routing rules can be configured to direct end users to Identity providers login based on these factors

a)

User's domain

b)

User's location

c)

All of them

d)

User's device

e)

User's app access

&

User's attributes

47.

When a group is pushed to Active Directory, OKTA is the profile master of the group

a)

FALSE

b)

TRUE

48.

What is the allowed length range for a password?

a)

8 to 16 characters

b)

8 to 30 characters

c)

4 to 16 characters

d)

4 to 30 characters

49.

Which is a true statement about API token?

a)

The category for API events in system log is Token Lifecycle

b)

API tokens are valid for 30 days and automatically renew when they are used with an API request

c)

The only time you can view the token is during the creation process.

d)

OKTA active AD agent tokens are managed by OKTA only

e)

Tokens are only valid if the user who created them is active

50.

Can you remove a Group from Active Directory provisioning?

a)

Yes, by removing the group from AD assignments

b)

No that cannot be done

51.

User can be activated when user is in the following state

a)

Suspended

b)

· ​

Inactive

c)

Staged

d)

Deactivated

e)

Pending Activation

52.

These administrators do not have their own set of available email notification types

a)

Third Party Admin

b)

App Admin

c)

Mobile Admin

d)

Org Admin

e)

Report Admin

53.

This option is available only if change password is enabled

· ​

a)

perform self-service password unlock

b)

perform self-service password reset

c)

perform self-service password reset and unlock

54.

Auto-confirm imported users can be configured during which process

a)

Provisioning (To OKTA)

b)

General Settings

c)

Directory Integration

d)

Manual import

55.

How many default attributes can a OKTA master profile offer?

a)

50 attributes

b)

31 attributes

c)

30 attributes

d)

25 attributes

56.

OKTA Browser Plugin uses this to connect to the SWA apps

a)

TLS

b)

SSL pinning

c)

SSL

d)

URL string match

57.

You can create Custom User Types for the following types of profiles

a)

OKTA User Profile only

b)

OKTA and Application User Profile only

c)

OKTA and Identity Provider User Profiles

d)

Application User Profile only

58.

These are few common issues seen if SAML is configured incorrectly

a)

User experiences endless loop being redirected to OKTA login and then to application's standard login page

b)

Identity Provider certificate has expired

c)

Throws an error saying username is invalid or not found

d)

User is taken to standard login page of Application instead of SSO page

59.

Which Administrator can manage Profile Editor but not Profile mappings?

a)

API Access Management Admin

b)

Group Admin

c)

Org Admin

d)

App Admin

60.

Bulk password reset cannot be performed on OKTA mastered users

a)

TRUE

b)

FALSE

61.

How can you enable Organizational Unit updates on an OKTA user profile?

a)

By enabling "Update OU when the group that provisions a user to AD changes " in Provisioning

b)

During Group Push operation

c)

During Incremental Import process

d)

During Directory Integration

62.

Which app simulates IDP initiated flow for a SP initiated app?

a)

Bookmark simulator

b)

IDP Simulator app

c)

Bookmark App

d)

SP initiator

63.

OKTA username format can be one of these

a)

UPN (User Principal Name)

b)

<Sam account name><configurable suffix>

c)

Custom name using OKTA expression language

d)

<Sam account name>@<domain name>

e)

Email address

64.

You can configure an OKTA User Profile to use a speicific Profile Master using the following feature

a)

Master priority in OKTA user profile

b)

Changing the order in Profile Master

c)

Import from a specific app or directory

65.

Converting an individual application assignments to group assignments will result in

a)

Users will losing access to application, if group is unassigned from the application

b)

deactivating the individual assignments

c)

·

disable provisioning individual users

d)

User properties being managed by the group

66.

Is this a capability to configure from Appearance settings?

a)

Change color scheme on My Applications home page

b)

Add a logo to the org

c)

Upload Sign in background image

d)

Add custom links to your home page

e)

Enable OKTA footer on End users home page

67.

Matching rules

a)

Allow partial match on first and last name

b)

Allow exact match on a single or combination of attributes

c)

Auto-confirm partial or exact matches

d)

Auto activate new users

e)

Allow exact match to OKTA user if email matches

&

Auto confirm new users

68.

Administrator finds this error in Dashboard->Tasks page in OKTA. What could be possible cause of this error? Insufficient account permissions on the account used to setup the API config

a)

API integration user account might have lost the required permissions

b)

Password for the API integration user might have changed

c)

API username might have changed

d)

API integration account might have expired

69.

When a message "User is now in one-time password mode" is displayed on People page, what action might have taken on the user?

a)

Reset Password

b)

Unlock user

c)

Activate user

d)

Expire Password

70.

What are some of the limitations for Factor sequencing?

a)

Cannot configure in Application sign on policies

b)

If an org uses both Delegated authentication and Factor sequencing , then AD account status is not checked during sign-in flow unless the password MFA factor is enabled

c)

SAML based MFA or Identity Providers cannot be used as part of Factor Sequencing chain

d)

If the sign-on policy has multiple factor chains, the user must be enrolled in the first factor from at least one factor chain.

71.

What is true about the deactivation of an user?

a)

Can be deleted

b)

Deactivated user loses access to OKTA and unassigned from applications

c)

Deactivated user can login but cannot access applications

d)

Can be reactivated

e)

Deactivated user cannot login to OKTA

&

Can activate in bulk

72.

Which feature can be used to activate the users and update their group memberships when users are authenticated using AD?

a)

Just-In-Time provisioning with delegated authentication

b)

Directory Integration

c)

Agentless Desktop SSO

d)

Incremental Import

73.

SAML can either be used in IdP initiated flows or SP initiated flows

a)

TRUE

b)

FALSE

74.

What are some of the key benefits of Social Authentication?

a)

No need to maintain separate user database, sign on and authentication infrastructure

b)

Users do not need to remember additional password

c)

Ensure quick and easy registration to custom apps

d)

Easily assign applications

e)

JIT can be enabled to create OKTA user profiles

75.

Multiple AD groups can be mapped to a single OKTA group

a)

TRUE

b)

FALSE

76.

MFA can be configured at the following level

a)

OKTA org level

b)

OKTA org level or Application level or both

c)

Application level

d)

OKTA org level or Application level

77.

Admins will only receive emails for groups, apps, or users that they have permission to view.

a)

TRUE

b)

· ​

FALSE

78.

Which actions can be taken on import results (imported users in Import screen)?

a)

Confirm the Exact match user assignment which will import the user into OKTA and link to existing matched OKTA user

b)

Select an existing OKTA user and link the imported user

c)

Update user attributes

d)

Confirm import of New User when there is no matching user in OKTA

e)

Ignore the assignment which will not import the user into OKTA

79.

Universal Directory allows you to construct custom OKTA usernames or application usernames with Universal Directory's data and expression language.

a)

FALSE

b)

TRUE

80.

Network zones may be incorporated into

a)

VPN Notifications

b)

Password Policies

c)

Factor Enrollment policies

d)

Application Sign-on policies

e)

IWA

81.

Which statement is true about password reset?

a)

Administrator can reset passwords even for a suspended user

b)

A self service option is available for password reset

c)

When a password is reset, all applications assigned to the user that support Provisioning and are Sync Password enabled are updated with the new password.

d)

A temporary password can be sent to the OKTA mastered user after resetting the password

82.

Which type of Administrators CANNOT do Password and MFA resets?

a)

Help Desk Admin

b)

Group Admin

c)

Org Admin

d)

API Access Management Admin

e)

Report Admin

83.

You can configure the following feature not to create new users during an import

a)

Disable activate email

b)

Do not import users

c)

JIT provisioning

d)

Schedule import

84.

Which one is a true statement about Group rules?

a)

By default, a newly created rule is active

b)

OKTA Expression language can be used to create complex rules based on a combination of user or group attributes

c)

Group Rules are org wide rules

d)

User cannot be in pending or inactive state to move to an assigned group

85.

What is the minimum and maximum number of characters a password recovery answer should contain (security answer)?

a)

1-50 characters

b)

4-30 characters

c)

4-50 characters

d)

8 - 50 characters

86.

In which policies, can you exclude or include Users based on Location (Network Zones) in which policies?

a)

Application Sign on and OKTA Sign on Policies

b)

OKTA Sign on policy

c)

Application Sign on Policy only

d)

OKTA Sign on, Application sign on and Password Policies only

e)

Factor enrollment policy

&

Password Policy

87.

How is the username identified in Password Complexity requirements?

a)

Display Name field on OKTA master profile

b)

Username field on OKTA master profile

c)

string before @ symbol in user's email address for OKTA mastered users

d)

string before @ symbol in user's email address for Active Directory mastered users

e)

Display name for Active Directory mastered users

88.

Non pre-built OIN applications can be connected through these protocols

a)

OID

b)

SAML

c)

SWA

d)

SCIM

e)

Kerberos

89.

Is this an Early Access feature?

a)

Windows Autopilot Enrollment Policy

b)

Allow end-users to quickly access everyday apps in the OKTA Browser Plugin

c)

Risk Based Authentication

d)

Import Monitoring Dashboard

e)

Phishing Resistant OKTA Verify Push

&

Factor Sequencing

90.

Which Profiles allow creation of new custom attributes in schema?

a)

Identity Provider profiles

b)

Directory profiles

c)

Application user profile

d)

OKTA user profiles

91.

What is required to setup AD authenticated on-prem applications in OKTA?

a)

Delegated Authentication

b)

SWA enabled application setup

c)

SAML enabled application setup

d)

Use OKTA username and password to sign into OKTA

92.

Is this a pre-requisite for configuring Group push?

a)

API authentication must be enabled

b)

Provisioning to app should be enabled

c)

For AD, OKTA service account must have permission to create groups

d)

OKTA group must be assigned to app before push

e)

All members of the group to be pushed must have been provisioned and assigned to app before group push is configured

93.

Which provisioning option does not allow editing users from within Office 365 directly?

a)

Universal Sync

b)

Profile Sync

c)

Licenses\Roles Management Only

d)

User Sync

94.

End users will be able to add apps using OKTA Browser plugin, Provided the app is allowed to be added in the Application Self Service settings

a)

FALSE

b)

TRUE

95.

Super Admins can set default email notifications for all administrators

a)

TRUE

b)

FALSE

96.

An API token is issued for a specific user and all requests with the token act on behalf of the user.

a)

FALSE

b)

TRUE

97.

Federation Broker mode is an Early access feature. What is not true about this feature?

a)

Its not available for OIN apps

b)

Provisioning is not available if this feature is turned on

c)

Import is not available along with this feature

d)

Users or groups can still be assigned to the application

e)

Works for SP initiated flows only

98.

Disconnect from AD option is accessible from

a)

Administrator Dashboard

b)

Directory Integrations->Assignments

c)

Application Assignments

d)

Directory->People

99.

OKTA uses this to transform profile attributes

a)

OKTA Expression

b)

OKTA Expression Language

c)

OKTA Expression editor

d)

OKTA Expression qualifier

100.

What are some of the pre-requisites to install an OKTA AD agent?

a)

Install Agent on 2 or more host servers to ensure high availability

b)

NET 4.5.2 or higher must be installed

c)

Host servers should be a member in the AD domain

d)

Host server and the users can be different domain as long as host server is in the same AD forest

e)

if there are 30k or more users, deploy minimum of 3 or more OKTA AD agents

101.

As part of Password Policy, Self service password unlock can be configured for

a)

OKTA mastered users

b)

AD mastered users

c)

Both OKTA and Active Directory mastered users

d)

Cannot be configured as part of password policy

102.

Which option is not available for Password unlock?

a)

Voice call and Email

b)

SMS and Email

&

SMS and Voice call

c)

Email

d)

Voice Call

e)

SMS

103.

Which Application Self-service option should be enabled to configure Access request workflow for an organization application?

a)

Allow users to add org-managed apps

b)

Allow users to add personal apps

c)

Approval Required

d)

Allow users to email "Technical contact" to request an app

104.

This option when enabled will not allow browser to remember passwords for the apps

a)

Prevent web browsers from saving sign-in credentials

b)

Disable browser password prompts

c)

Recommend strong passwords for apps

d)

Prompts to save apps to your Dashboard

105.

Which feature allows to add additional user attributes during import?

a)

Provisioning mapping

b)

Schema discovery

c)

Import from CSV

d)

source from profile master

e)

Import User Schema

106.

OKTA Policy Framework principle is based on XACML principle which means

a)

More restrictive policies are of lowest priority

b)

Default policies should be on top ladder

c)

Follows top down approach

d)

Default policies should have highest priority

e)

More restrictive policies should be of highest priority

107.

Which self-service options can be configured for account recovery?

a)

OKTA Verify

b)

SMS

c)

Email

d)

Voice Call

e)

Yubi Key

108.

When integrating OKTA with Office 365, its recommended to use an Admin account which is not part of the domain that's being federated because

a)

Admin account that's outside the domain cannot be provisioned

b)

To enable specific logging

c)

To prevent lock out of admin account

d)

To allow back door access to Office 365 in case of troubleshooting

109.

Select all that is true for Password Age configuration

a)

Users will not receive expiry warning if the password expiry after setting is set to less than 6 days

b)

Password expires after setting does not appear for AD mastered users

c)

Minimum time required between password changes can set to a maximum value of 9999 mts

d)

Password expiry cannot be accurately calculated for users created before March 10, 2014

e)

Maximum number of passwords that the user can use before he can reuse the password is 30


&

Maximum value that can be set for password expiry and also for prompt users to change their password is 999 days

110.

Universal Directory supports

a)

Directory profiles

b)

Active Directory group profiles

c)

Application profiles

&

OKTA user profiles

d)

Identity Provider Profiles

e)

OKTA group profiles

111.

Password Policies can be applied on the following types of users:

a)

OKTA, Directory and Identity provider profiles

b)

Directory Mastered Users only

c)

Application mastered

d)

OKTA and Directory Mastered Users only

e)

OKTA Mastered users only

112.

Which option can warns users when orgs other than the primary OKTA org are accessed?

a)

Turn on black list orgs

b)

Turn on security warning

c)

Turn on security warning and anti-phishing whitelist

d)

Turn off whitelist orgs

113.

API tokens issued to OKTA agents can be revoked by Administrator regardless of the token state.

a)

FALSE

b)

TRUE

114.

You can choose to Auto-activate AD users

a)

Cannot auto-activate users

b)

When setting up Provisioning

c)

When setting up Self service options

d)

During Import process

115.

When an application is mentioned as OKTA Verified, it means

a)

It means you can provision users to applications

b)

OKTA verified is same as SWA

c)

Application was created either in OIN or by OKTA user community and verified by OKTA engineers

d)

Application has been verified and tested by OKTA community

e)

Application was created by OKTA Engineers

116.

Which option allows Password reveal feature to be available to admin only?

a)

Administrator sets username and password

b)

Administrator sets username and user sets password

c)

Users share single username and password set by Administrator

d)

Administrator sets username and password same as OKTA username and password

e)

User sets username and password

117.

An administrator will be able to reset selected MFA factors when resetting MFA for all users

a)

FALSE

b)

TRUE

118.

What is the retention period for System Logs?

a)

6 months

b)

None

c)

3 months

d)

1 year

119.

Password soft lock functionality can be implemented for AD mastered users by

a)

Setting the value of "Lock out user after X unsuccessful attempts" in Active Directory Password Policy to a number equal to AD failed sign ins

b)

Setting the value of "Lock out user after X unsuccessful attempts" in Active Directory Password Policy to a number more than that of AD failed sign ins

c)

Configuring Self Service option for Unlock Accounts

d)

Setting the value of "Lock out user after X unsuccessful attempts" in Active Directory Password Policy to a number less than that of AD failed sign ins