Account lockout policy

Add account lockout when the login attempt fails multiple times over short period of time.

This mechanism would help to protect against unauthorized access, especially brute-force attacks.

Preferably it could be expanded to be configurable at organization settings level;

  • Account Lockout – The account is temporarily or permanently disabled after a set number of failed login attempts.

  • Lockout Threshold – The number of failed attempts allowed before locking the account.

  • Lockout Duration – How long the account remains locked

  • Exponential Backoff – Increase wait time between attempts instead of a full lockout.

  • Rate Limiting – How many login attempts can be made in a certain time frame

Please authenticate to join the conversation.

Upvoters
Status

In Review

Board

💡 Feature Request

Date

7 months ago

Author

Michał Muszyński

Subscribe to post

Get notified by email when there are changes.