Hey @LinkinShan! :gigipixel: Looks like your password lockout policy is missing - Could you try adding that first through an API call and let me know if you're still experiencing this issue?
Add new password lockout settings on the organization level. This will overwrite the settings set on the instance for this organization. The settings specify when a user should be locked (e.g how many password attempts). The user has to be unlocked by an administrator afterward.