If I set Account Lockout Duration to 0 requiring an admin to unlock IDs…. What happens if all the admin accounts get locked? A malicious user, password-guessing worm, or even an admin running a security scanner that checks password of all the IDs in the domain, could do the trick. Am I correct in thinking that if this happens in a root domain it would be time to start over and completely rebuild?