Designates whether or not users who visit the password reset portal should be given the option to unlock their on-premises ...

Designates whether or not users who visit the password reset portal should be given the option to unlock their on-premises Active Directory accounts without resetting their password.  By default, Azure AD will always unlock accounts when performing a password reset, this setting allows you to separate those two operations.

If set to "yes", then users will be given the option to reset their password and unlock the account, or to unlock without resetting the password. 

If set to "no", then users will only be able to perform a combined password reset and account unlock operation.