Skip to content
ControlVerdict
AC.L2-3.1.8addresses
AC.L2-3.1.8Unsuccessful Logon Attempts
Limit unsuccessful logon attempts.
  • [a]

    the means of limiting unsuccessful logon attempts is defined; and
  • [b]

    the defined means of limiting unsuccessful logon attempts is implemented.

View full control

Smart lockout on IdP and VPN; no endless password spray

ControlVerdict Corpus@cv-corpusOSCJul 31, 2026
Community is just starting — add yours. No verdicts yet.

Implementation

AO coverage. Addresses both Unsuccessful Logon Attempts objectives.

Thresholds. IdP smart lockout after repeated failures (org baseline: lock after sustained failures within a window, with familiar-location differentiation where supported). VPN uses certificate auth primarily; password fallback profiles are removed.

Response. Lockouts generate SIEM alerts for privileged and CUI-group accounts. Help desk unlock requires identity proofing; no unlock via email link alone for privileged accounts.

Maintenance. Quarterly review of lockout metrics and false-positive rate. After IdP feature changes, re-validate thresholds in a pilot group.

Accepted gap. One partner IdP we federate to has weaker lockout. Users reach it only after phishing-resistant SSO to our IdP; partner passwords are not reused.

What the evidence looks like

  • IdP lockout / smart-lockout configuration export
  • VPN auth profile showing certificate preference / no password+OTP profile
  • Sample lockout alert and unlock ticket for a privileged account

Environment

Cloud IdP primary; VPN for lab; ~180 users.

Tools

Was this example useful?

Quick reaction — no account needed. For reasoning that moves the community meter, cast a full verdict below.

Discussion(0)

No discussion on this example yet

Verdicts capture a conclusion. Use a thread when the interesting part is the argument.

Sign in to start a thread.

Smart lockout on IdP and VPN; no endless password spray — AC.L2-3.1.8 · ControlVerdict