AC.L2-3.1.8Unsuccessful Logon Attempts
Limit unsuccessful logon attempts.
[a]
the means of limiting unsuccessful logon attempts is defined; and[b]
the defined means of limiting unsuccessful logon attempts is implemented.
Smart lockout on IdP and VPN; no endless password spray
Implementation
AO coverage. Addresses both Unsuccessful Logon Attempts objectives.
Thresholds. IdP smart lockout after repeated failures (org baseline: lock after sustained failures within a window, with familiar-location differentiation where supported). VPN uses certificate auth primarily; password fallback profiles are removed.
Response. Lockouts generate SIEM alerts for privileged and CUI-group accounts. Help desk unlock requires identity proofing; no unlock via email link alone for privileged accounts.
Maintenance. Quarterly review of lockout metrics and false-positive rate. After IdP feature changes, re-validate thresholds in a pilot group.
Accepted gap. One partner IdP we federate to has weaker lockout. Users reach it only after phishing-resistant SSO to our IdP; partner passwords are not reused.
What the evidence looks like
- IdP lockout / smart-lockout configuration export
- VPN auth profile showing certificate preference / no password+OTP profile
- Sample lockout alert and unlock ticket for a privileged account
Environment
Tools
Was this example useful?
Quick reaction — no account needed. For reasoning that moves the community meter, cast a full verdict below.
Discussion(0)
No discussion on this example yet
Verdicts capture a conclusion. Use a thread when the interesting part is the argument.
Sign in to start a thread.