User-unlock - Ipa
$ ipa user-show jsmith --all | grep "Account lockout" Account lockout status: False
By default, the ability to unlock accounts is restricted to administrators to prevent unauthorized access. However, you can delegate this task to helpdesk staff or junior admins by creating specific roles and privileges. ipa user-unlock