Someone leaves the company. You open their account and switch it off. Two weeks later they click Forgot password, pick a new one, and they are back in your master data.
That worked in Primentra until this week. We found it ourselves, with a test that went red on 2 October, before any customer did. The same shape sits in a lot of home-built user tables, so here is how it happened.
One flag, three owners
A user had one switch: active or inactive. Three different things wrote to it.
An administrator cleared it to turn off a leaver. Primentra cleared it after five wrong passwords, to stop someone guessing. And the password reset set it back to active, because a user who proves they own the mailbox should get back in after a lockout.
Each rule made sense alone. Together they meant the reset could not tell a lockout from a leaver. It saw inactive and switched it on, and the administrator's decision was gone.
There was a second gap. Switching a user off stopped the next sign-in, but a session already open kept running. A leaver with a browser tab open on their last day kept working until the session timed out.
Disabled and locked out ask different questions
SQL Server sorted this out long ago. An administrator can disable a login, and the password policy can lock it out. Two flags. Clearing one never clears the other.
Disabled answers: is this person allowed in at all? That is an HR question, and only an administrator should answer it.
Locked out answers: is somebody guessing this password? That is a security event. The system sets it, and a person with authority looks at it before it clears.
Put both in one flag and every path that clears one clears both. The password reset is the obvious path. A bulk import that writes the active column is another. So is the SQL script someone runs to unlock everybody on a Monday morning.
What changed in 1.2026.10.7
The Users screen now has two settings under Sign-in status: Enabled and Locked out. The list shows a badge per state: Active, Disabled or Locked out. A user can be disabled and locked out at once.
Only an administrator ticks or clears Enabled. Primentra sets Locked out after five wrong passwords, and only an administrator clears it. You cannot lock someone by hand, so the red badge means one thing only. To block a person, clear Enabled.
Forgot password no longer touches either flag. It changes the password of an enabled user. A locked user can set a new password but cannot sign in until an administrator clears the lock, and the reset screen says so. A disabled user gets no reset mail. The message on screen stays the same either way, so a stranger cannot use the form to find out which accounts are disabled.
Clearing Enabled and a lockout both end every open session of that user and cancel unused sign-in links. Each real change goes to the audit log as user_disabled, user_enabled, account_locked or account_unlocked, with who did it.
One exception. An administrator's own lock clears at the next sign-in 30 minutes after it was set. Without that, five wrong guesses per name could lock out every administrator, and nobody would be left to unlock anyone. For the day it goes wrong anyway, the recovery tool gets you back in.
What this costs you
A locked user now needs an administrator. Forgot password used to handle that alone, so expect a few more tickets. We chose that on purpose. A lock means somebody may have been guessing, and a person should look before it clears.
Anyone who knows a user's e-mail address can also sign that user out, by typing five wrong passwords. We accepted that too. The alternative was a lock that leaves the target signed in while someone guesses.
Check your own user table
If your team built its own tool on a user table, find the column that means "can sign in". Then list everything that writes to it: the admin screen, the password reset, the lockout, the import, the nightly sync from HR. If two of those write the same bit, a leaver can come back through the one you forgot.
Teams that leave Active Directory behind first have to decide who turns a leaver off. This post is about the next step: making sure they stay off.
Common questions
Can Forgot password unlock an account?
No. It changes the password of an enabled user and nothing else. A locked user still cannot sign in until an administrator clears Locked out, and the reset screen says so. A disabled user gets no mail at all.
Does switching a user off end the session they have open?
Yes. Clearing Enabled ends every open session of that user and cancels unused sign-in links. A lockout does the same.
Can I lock a user by hand?
No. To block someone, clear Enabled. Only Primentra sets Locked out, so the badge always means one thing: somebody typed five wrong passwords.
What if every administrator is locked out?
An administrator lock clears at the next sign-in 30 minutes after it was set. If that is not enough, the recovery tool on the server gets you back in.
Upgrading to 1.2026.10.7? Make a backup first. Users who were inactive before the upgrade show as Disabled afterwards.