Hi Team,
Thank you Dave for analysing & providing the requirement for this issue. Please find below scenarios which I have compiled.
For INTERNAL USERS, they would be able to reset login attempts by:
1. Resetting password via reset link - User has to reset password by their own (this won't work for undeliverable email ids)
2. Resetting only login attempts - Admin will be able to reset only login attempts of a particular user, so that user would try again to login with the same password.
3. Resetting login attempts with reset password - Admin will reset password, and will share it with the user. Users would be able to login with this new password again.
I feel the 1st & 3rd options are reliable and good to go.
A still or wireframe for user management for Admin:

For LDAP & KERBEROS:
As per my understanding, we don't provide reset passwords for LDAP & KERBEROS, so we can't lock those users, and let users be allowed to attempt login as we have it currently.
Let me know if this works.
--
Rahul Shirsat
Senior Software Engineer | EnterpriseDB Corporation.