Account lockout policy
Add account lockout when the login attempt fails multiple times over short period of time.
This mechanism would help to protect against unauthorized access, especially brute-force attacks.
Preferably it could be expanded to be configurable at organization settings level;
Account Lockout – The account is temporarily or permanently disabled after a set number of failed login attempts.
Lockout Threshold – The number of failed attempts allowed before locking the account.
Lockout Duration – How long the account remains locked
Exponential Backoff – Increase wait time between attempts instead of a full lockout.
Rate Limiting – How many login attempts can be made in a certain time frame
Log in to comment and vote
No comments yet
Be the first to share your thoughts.