Lockout window insufficient |
---|
Risk Level: | Low | Check or Attack Name: Lockout Window |
---|---|---|
Platforms: | Windows NT | |
Description: | The lockout observation window is less than the value specified in the current policy. The Lockout Window specifies what period of time passes before the incorrect login count is reset. If the duration is too short, or if account lockouts are not enabled, attackers can more easily brute force your accounts. |
|
Remedy: | Set the Reset Count After value so that it equals or exceeds the Lockout Window value in the current policy. To change the account lockout duration, follow these steps:
|
|
References: |
Know Your Risks |