Skip to main content

Account lockout policy

Add account lockout when the login attempt fails multiple times over short period of time.

This mechanism would help to protect against unauthorized access, especially brute-force attacks.

Preferably it could be expanded to be configurable at organization settings level;

  • Account Lockout – The account is temporarily or permanently disabled after a set number of failed login attempts.

  • Lockout Threshold – The number of failed attempts allowed before locking the account.

  • Lockout Duration – How long the account remains locked

  • Exponential Backoff – Increase wait time between attempts instead of a full lockout.

  • Rate Limiting – How many login attempts can be made in a certain time frame

Log in to comment and vote

No comments yet

Be the first to share your thoughts.