Add account lockout when the login attempt fails multiple times over short period of time.
This mechanism would help to protect against unauthorized access, especially brute-force attacks.
Preferably it could be expanded to be configurable at organization settings level;
Account Lockout – The account is temporarily or permanently disabled after a set number of failed login attempts.
Lockout Threshold – The number of failed attempts allowed before locking the account.
Lockout Duration – How long the account remains locked
Exponential Backoff – Increase wait time between attempts instead of a full lockout.
Rate Limiting – How many login attempts can be made in a certain time frame
Please authenticate to join the conversation.
In Review
💡 Feature Request
7 months ago

Michał Muszyński
Get notified by email when there are changes.
In Review
💡 Feature Request
7 months ago

Michał Muszyński
Get notified by email when there are changes.