You are viewing limited content. For full access, please sign in.

Question

Question

Access Rights Effective Rights Showing "Account locked. [9011]"

asked on September 17, 2025

I have a user that is having issues seeing images in the Web Client. She receives the error message "Access denied. [9013]".

When I look in the repository and try to view the Access Rights Effective Rights for the user, it says "Account locked. [9011]". The user account is an AD account. Why would it say that the account is locked?

We are using Laserfiche Web Client 12.0.2505.796.

0 0

Replies

replied on November 13, 2025

Blake,

 

Afternoon sir. Did you ever find out what the fix was for this? 

0 0
replied on November 18, 2025

I encountered the same 9011 error when attempting to view the Effective Rights of Active Directory accounts. The admin was able to resolve the issue using this resource.

0 0
replied on February 20 • Show version history

I don't see that this was ever fully answered, and I'm now seeing the issue with my users. I am not able to find a lock anywhere (AD, LFDS, LF Admin Console). Does anyone have any suggestions? 

Edit: I am noticing this with all users, not just one. It happens when I try to look at Effective Rights, both in the Windows and the web clients. The users are not disabled in either LFDS or AD, and neither is my account.

 

0 0
replied on February 23 • Show version history

I’m not entirely certain of the underlying cause yet, but applying the standard steps to explicitly enable TLS 1.2 has resolved the 9011 error for several clients I worked with.

This has been effective even in environments running newer server operating systems where TLS 1.2 is enabled by default and license activation (which explicitly requires TLS 1.2) was already successful.

In a few cases, clients later confirmed they had performed in-place operating system upgrades. My suspicion is that remnants of the previous OS configuration may be contributing to the issue. This would also explain why enabling RC4 initially resolved the problem for one client early in my troubleshooting, prior to fully enforcing TLS 1.2.

0 0
replied on February 20

I had to find another way to get what I was looking for to finish a project, but I need to circle back around to this to get details and figure out why it does this.

0 0
replied on February 24

I am pretty sure it is trying to say your account is locked, and not able to view effective rights for this account, not that her account is locked. Even if her account was locked, you could still view effective rights.

0 0
replied on February 24 • Show version history

Ok - is there a way to check if my account is locked? Everything else I do seems to be working fine. My account isn't disabled in LFDS or AD.

0 0
replied on February 24

If my account was locked, I would not be able to log into Laserfiche.

0 0
replied on February 24

But the user your trying to view effective rights for is also able to login to Laserfiche, so if having a locked account means you can not login, then they certainly are not locked either.

I get the account locked error anytime I try to view effective rights for any account or select any user in the web administration console. These users can login and use the system. Also there is no "lock" property on an account, so I believe account locked is not the same meaning as disabling an account which is when prevents them from logging in.

0 0
replied on May 7

Is there an open case for this at LF?

0 0
replied on May 13 • Show version history

We do have a support case opened on this since Feb 26th but we just keep going round and round in circles without getting anywhere closer to an explanation. Honestly there is no logic in this. As Blake said, you can not login with a locked account and as I said, you can still view the effective rights of a locked account because locked accounts and effective rights are not related in any way.

I will follow up with support and continue going round and round

0 0
replied on May 13

Ok...appreciate the follow-up.

0 0
replied on February 24

I can get the same error message in the Windows Client and it has these error details:

Error Code: 9011
Error Message: Account locked. [9011]

------------ Technical Details: ------------

LFSO:
    Call Stack: (Exception)
        LFSession::ProcessResponse
        LFSession::SendRequest (XCALCACCESS /+LF/entry/1)
        CLFEffectiveRights::CreateForDispatch
        ILFEntryImpl::get_EffectiveRightsByTrustee
    Additional Details:
        HRESULT: 0xc0042333 (LFSession::ProcessResponse, LFSession.cpp:3903)
         (LFSO/12.0.2510.972)
lf.exe (12.0.2510.972):
    Call Stack: (Current)
        CEffectiveRightsTab::OnBnClickedBtnChooseTrustee
    Additional Details:
        Exception: 0xc0042333 [9011] (Account locked.) (CEffectiveRightsTab::OnBnClickedBtnChooseTrustee at EffectiveRightsTab.cpp:365)
    Call History:
        IdleTimerProc
        CTrusteeListCtrl::InitializeCollection
        CTrusteeListCtrl::FillList
        IdleTimerProc
        IdleTimerProc
        IdleTimerProc
        CChooseTrusteeDialog::OnBnClickedOk
        CEffectiveRightsTab::OnBnClickedBtnChooseTrustee

 

0 0
replied on May 13

I just opened a support ticket with my SP. If you are experiencing the same issue, I would encourage you to open one with your SP as well so they have more information to look at to narrow down the cause.

0 0
replied on May 13

Blake, they told me it is because the repository is authenticating with the SQL server via SQL Authentication instead of Windows Auth. We have been authenticating to SQL servers with the Laserfiche services across the country using SQL Auth for over a decade. Are they telling you the same thing?

0 0
replied on May 13

That can't be the reason because we use Windows Authentication. My SP said that they had success with resolving the error by implementing the registry keys for TLS 1.2, so I am currently waiting until I can restart my server to see if that had any affect.

0 0
replied on May 13

Exactly, I can not understand the logical connection between how the database connection is established and Laserfiche user lockouts. This is why I don't like opening support cases and would rather find a solution on answers.

I saw Cassandra's post but would rather not modify the registry without good reason, I tend to let Microsoft handle the TLS environment as I don't want to break other systems.

Let me know how it goes and if no other fires start.

0 0
replied on May 15

As expected, the TLS registry changes did not fix the issue. I have just sent the SP the log and trace files they requested.

0 0
replied on May 13

@████████ - do you have a case open with LF? If not, can you open a case as well, so we have more visibility and information shared with LF support.

0 0
You are not allowed to follow up in this post.

Sign in to reply to this post.