I have ran into issues where a Mac OSx 10.6.x or 10.7.x that is joined to a Active Directory Domain can’t login. The login screen just shakes. A new person that has never logged into the computer can sign in just fine as it will create a “managed” account using Active Directory. If we log in as an Administrator and look at the User and Group in System Preferences the User Account is no longer shown as “Managed”.
By all indictions it appears as if the user has locked their local account as they probably fat fingered it too many times. The only solution I have found was to run the following command in bold below from a terminal screen. This is done from an Administrator account. After I have done this command, the user can log back in and all of their settings and documents are intact. If there is another solution please leave a comment.
sudo dscl . delete /Users/username