Good day, there is a need to obtain a list of AD accounts lock which occurred because of wrong password. To obtain such a list is necessary through LDAP query. There is such an attribute on the user account lockouttime which keeps the lock time accounts if you use this attribute the situation when SABIS account was unlocked automatically (I have automatic account rasplachivaetsya 30 minutes after blocking) that lockouttime is not reset and it turns out that using a query like account as blocked but in fact quite different. Also according to msdn is the attribute msDS-User-Account-Control-Computed which is just the same and holds the state accounts, but to use ldap filters to queries it is not as it calculated, and how to use it anywhere else not really described. Do Ldap queries using perl scripts on Linux server, so that PowerShell does not offer. Thank you.