Re: Account Lockout Threshold Not Working

From: Steven L Umbach (n9rou_at_nospam-comcast.net)
Date: 06/23/04

  • Next message: Steven L Umbach: "Re: Unencrype file"
    Date: Wed, 23 Jun 2004 21:52:31 GMT
    
    

    Domain level is where that policy needs to be configured. You can run "net accounts"
    on a domain controller to see what the threshold is. What may have happened is that
    the operating system often interprets one bad logon attempt by the user as multiple
    logon failures. That is one reason why MS recommends 10 as the lockout threshold
    assuming users need to use reasonably secure passwords. The links below may be
    helpful. --- Steve

    http://www.microsoft.com/downloads/details.aspx?FamilyID=8c8e0d90-a13b-4977-a4fc-3e2b67e3748e&displaylang=en
    http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/bpactlck.mspx

    "-=gu=-" <anonymous@discussions.microsoft.com> wrote in message
    news:2096c01c45964$6ce4c470$a101280a@phx.gbl...
    > Hi,
    > On my DC, in Domain Security Policy... In Windows
    > Settings, Security Settings, Account Policies, the
    > Account Lockout Threshold is set for 5 invalid attempts.
    > I set this myself about a year ago but never tested it.
    > Just found out from a user and proved it myself that the
    > lockout occurs at 3 bad attempts. Am I setting this in
    > the wrong place? Any help / much appreciated!
    > Thanks! -=gu=-


  • Next message: Steven L Umbach: "Re: Unencrype file"

    Relevant Pages

    • Re: Please help me, it is highly Urgent.............
      ... The reason why the threshold is given as 5 is because of security concern. ... with credentials that subsequently expired. ... Account lockout duration = 0 ... Persistent drives may have been established ...
      (microsoft.public.windows.server.active_directory)
    • Re: Account Lockout Policy
      ... I had thought this was cured with SP1. ... threshold in the 50 minute area or more. ... Have you enabled auditing of security events for login ... > Account lockout thershold = 3 invalid login attempts ...
      (microsoft.public.windowsxp.security_admin)
    • Re: An Empirical Nonlinear Filter / A Flash
      ... about the look-back hold approach is that it only takes into account the ... leading edge of the transient response of the averager and not the ... trailing edge. ... When the 30-day average exceeds the threshold, ...
      (comp.dsp)
    • Re: An Empirical Nonlinear Filter / A Flash
      ... about the look-back hold approach is that it only takes into account the leading edge of the transient response of the averager and not the trailing edge. ... Compute the 30-day average with the purpose of filtering out single-sample maxima that may exceed the threshold. ...
      (comp.dsp)