Hi @gtcdesign , thank you for reaching out to us.
From the description above, it seems you have enabled the Immediately Lock Out invalid usernames option in the Brute Force Protection section.
Wordfence will immediately lock out anyone who attempts to log in with an invalid username when the option above is enabled. Please note that your real users may mistype their usernames and get locked out. We recommend enabling this feature for sites that have a low number of users, such as 1 or 2 administrators and/or possibly a few editors.
To disable this, access the WordFence> Firewall> Manage Brute Force Protection section and uncheck the Immediately lock out invalid usernames. Remember to save your changes.
You can also find and unblock the IP address of the users that are locked out on the Wordfence> Firewall > Blocking page. Select the checkbox next to the block entry, then click the “Unblock” button.
Just to confirm, are you using the default login flow or a membership plugin? If by any chance you are using WooCommerce please be sure to enable WooCommerce integration under Wordfence> Login Security> Settings .
Let me know if this helps.
Thanks,
Mark