Lockout threshold incorrect |
---|
Risk Level: | Low | Check or Attack Name: lockout |
---|---|---|
Platforms: | Windows NT | |
Description: | The lockout threshold is greater than the security policy requires. This situation allows an attacker to successfully attempt a brute force attack on any account. The lockout period should not be too long, or an attacker can use the lockout period in a denial of service attack. |
|
Remedy: | Set the Lockout After n Bad Logins value so that it equals or is less than the value in the current policy. To change an account lockout count, follow these steps:
|
|
References: |
Know Your Risks |