Skip to content

Local Account Group Details

Local Accounts List for Specific Group Page

This page shows all local accounts that belong to a specific local group across your managed workstations. Use it when you want to understand where a group exists, which accounts are members of it, and what actions can be taken on those accounts.

Each row represents a local account on a workstation that is a member of the selected group. The table helps you review:

  • The account name.
  • The workstation where the account exists.
  • Whether the account is currently enabled.
  • The password state, such as whether the password has been randomized before.
  • Other local groups that the same account belongs to on that workstation.

Below the page title, you can use the quick filters to narrow the list:

  • Current & Enabled: Shows accounts that currently exist and are enabled.
  • Never Randomized: Shows accounts whose password has never been randomized by Lockfy.
  • Randomization Overridden: Shows accounts whose password was randomized before but was later changed outside of Lockfy. This usually means the password no longer matches the value last set by Lockfy.
  • Randomized: Shows accounts whose password is currently managed through Lockfy randomization.

The list includes the following actions for each local account:

  • toggle_on Enable or disable the local account. This requires the workstation agent to be connected.
  • lock_reset Randomize the local account password.
  • password Generate a temporary password for the local account. This also requires the workstation agent to be connected.

The table also shows which other local groups the account belongs to on that workstation. Selecting one of those groups opens its group details page so you can continue investigating related memberships.

The table header includes additional actions:

  • download Export the current table data to Excel.
  • sync Reload the list.
Randomize Local Account Password

Select lock_reset to randomize a local account password. If the workstation is connected, the action runs immediately. If it is offline, the action is queued and runs when the agent reconnects.

The new password is generated on the workstation agent according to the policy configured in Passwords Randomization and Access. The agent updates the local account password and removes the generated value from memory without sending it to the server.

Randomize Local Account Password

To generate a temporary password, the workstation must be connected to the server.

Select password to open the Access Local Account blade. Fill in:

  • Lock & randomize after: How long the temporary password should remain valid.
  • Access Purpose: Why access is being requested.

The server sends the request to the agent, which generates the password using the temporary password policy configured in Passwords Randomization and Access. The password is then returned and displayed only once. If it is not recorded when shown, it cannot be retrieved later and a new request is required.

When the access window expires, the signed-in user is logged out and the password is randomized in memory. This schedule is stored on the agent, so it still executes even if the workstation later loses connection to the server.

If multiple temporary password requests are created for the same local account, Lockfy enforces the earliest expiration time. For example, if one request allows 5 minutes of access and another allows 15 minutes, sign-out and password randomization occur after 5 minutes. Avoid stacking temporary access requests for the same account.