OneSpan Authentication Server verifies the status of the user account found for the user attempting to log on:
If the user account is disabled, the authentication request is rejected.
A disabled user account can only be enabled by an administrator.
If the user account has expired because a specified expiration date has passed, the authentication request is rejected.
An expired user account can only be reset by an administrator.
If the user account has been suspended due to inactivity, the authentication request is rejected.
A suspended user account can only be reactivated by an administrator.
If the user account is locked, OneSpan Authentication Server verifies whether a user auto-unlock attempt is possible (see User account auto-unlock).
If any unlock retries are left and the calculated lock duration since the last authentication request has elapsed, OneSpan Authentication Server assumes a possible user auto-unlock attempt and allows the authentication request.
A locked user account that cannot be unlocked via user auto-unlock, can only be unlocked by an administrator.