Credential Policies in CUCM/CUC are defined and enforced on the credential, not the user itself. For an LDAP-synced user, that means CUCM can only lockout the PIN.
If you unlock an account in AD, Jabber logins should immediately succeed assuming that CUCM/CUC LDAP Authentication is pointing at a Domain Controller that knows the account has been unlocked. I believe the AD site replication timer, default of 15 minutes, will factor into that equation.