Your network consists of a single Active Directory domain. All servers run Windows Server 2003 Service Pack 2 (SP2).
All client computers run Windows XP Professional Service Pack 3 (SP3).
You need to ensure that locked out user accounts remain locked out until an administrator unlocks the accounts.
What should you do?
A.
In the Default Domain Policy, set the Account lockout duration to 0.
B.
In the Default Domain Policy, set the Account lockout duration to 99999.
C.
From Active Directory Users and Computers, select the Account is trusted for delegation option for all user accounts.
D.
From Active Directory Users and Computers, select the Account is sensitive and cannot be delegated option for all user accounts.