Lock what precisely?

If you lock the specific account from all login attempts, you have a DoS opportunity on your hands.

If you lock the specific account from specific IPs, botnets win.

And I doubt a company would have requirements like this, and cross-ip and cross-account attack validations in place.