Lockout duration insufficient |
---|
Risk Level: | Low | Check or Attack Name: Lockout Duration |
---|---|---|
Platforms: | Windows NT | |
Description: | The lockout duration is less than the value specified in the current policy. This value specifies how long an account is locked out if too many logon failures occur within the period of time specified by in User Manager. If the lockout duration is too short, or if account lockouts are not enabled, attackers can easily brute force your accounts. |
|
Remedy: | Set the lockout Duration value so that it equals or exceeds the value in the current policy. To change the account lockout duration, follow these steps:
|
|
References: |
Know Your Risks |