Skip to content
ControlVerdict
AC.L2-3.1.8CMMC Level 2Level 2

Unsuccessful Logon Attempts

Practice statement

Limit unsuccessful logon attempts.

Quoted verbatim from NIST SP 800-171 Rev. 2 §3.1.8.Source

The source document’s non-normative “Discussion” section is not reproduced here. ControlVerdict quotes normative text verbatim or omits it — it never paraphrases a standard. Follow the source link above for the full context.

Assessment Objectives(2)

An assessor determines each objective separately. “Mostly implemented” is not a result — every objective below has to stand on its own.

  1. [a]

    the means of limiting unsuccessful logon attempts is defined; and

    1 example covers this

  2. [b]

    the defined means of limiting unsuccessful logon attempts is implemented.

    1 example covers this

Objective text quoted verbatim from NIST SP 800-171A via the CMMC Level 2 assessment guide.

Implementation examples(1)

Submit your own example
  • addresses
    AC.L2-3.1.8Unsuccessful Logon Attempts
    Limit unsuccessful logon attempts.
    • [a]

      the means of limiting unsuccessful logon attempts is defined; and
    • [b]

      the defined means of limiting unsuccessful logon attempts is implemented.

    Smart lockout on IdP and VPN; no endless password spray

    ControlVerdict Corpus@cv-corpusOSCJul 31, 2026
    Community is just starting — add yours. No verdicts yet.

    Implementation

    AO coverage. Addresses both Unsuccessful Logon Attempts objectives.

    Thresholds. IdP smart lockout after repeated failures (org baseline: lock after sustained failures within a window, with familiar-location differentiation where supported). VPN uses certificate auth primarily; password fallback profiles are removed.

    Response. Lockouts generate SIEM alerts for privileged and CUI-group accounts. Help desk unlock requires identity proofing; no unlock via email link alone for privileged accounts.

    Maintenance. Quarterly review of lockout metrics and false-positive rate. After IdP feature changes, re-validate thresholds in a pilot group.

    Accepted gap. One partner IdP we federate to has weaker lockout. Users reach it only after phishing-resistant SSO to our IdP; partner passwords are not reused.

    What the evidence looks like

    • IdP lockout / smart-lockout configuration export
    • VPN auth profile showing certificate preference / no password+OTP profile
    • Sample lockout alert and unlock ticket for a privileged account

    Environment

    Cloud IdP primary; VPN for lab; ~180 users.

    Tools

Discussion(0)

No discussion on this control yet

Edge cases, scoping questions, and “would this pass?” scenarios belong here.

Sign in to start a thread.