Unsuccessful Logon Attempts
Practice statement
Limit unsuccessful logon attempts.
Quoted verbatim from NIST SP 800-171 Rev. 2 §3.1.8.Source
The source document’s non-normative “Discussion” section is not reproduced here. ControlVerdict quotes normative text verbatim or omits it — it never paraphrases a standard. Follow the source link above for the full context.
Assessment Objectives(2)
An assessor determines each objective separately. “Mostly implemented” is not a result — every objective below has to stand on its own.
- [a]
the means of limiting unsuccessful logon attempts is defined; and
1 example covers this
- [b]
the defined means of limiting unsuccessful logon attempts is implemented.
1 example covers this
Objective text quoted verbatim from NIST SP 800-171A via the CMMC Level 2 assessment guide.
Implementation examples(1)
Submit your own example- addresses
AC.L2-3.1.8Unsuccessful Logon Attempts
Limit unsuccessful logon attempts.
[a]
the means of limiting unsuccessful logon attempts is defined; and[b]
the defined means of limiting unsuccessful logon attempts is implemented.
Smart lockout on IdP and VPN; no endless password spray
ControlVerdict Corpus@cv-corpusOSCJul 31, 2026Community is just starting — add yours. No verdicts yet.Implementation
AO coverage. Addresses both Unsuccessful Logon Attempts objectives.
Thresholds. IdP smart lockout after repeated failures (org baseline: lock after sustained failures within a window, with familiar-location differentiation where supported). VPN uses certificate auth primarily; password fallback profiles are removed.
Response. Lockouts generate SIEM alerts for privileged and CUI-group accounts. Help desk unlock requires identity proofing; no unlock via email link alone for privileged accounts.
Maintenance. Quarterly review of lockout metrics and false-positive rate. After IdP feature changes, re-validate thresholds in a pilot group.
Accepted gap. One partner IdP we federate to has weaker lockout. Users reach it only after phishing-resistant SSO to our IdP; partner passwords are not reused.
What the evidence looks like
- IdP lockout / smart-lockout configuration export
- VPN auth profile showing certificate preference / no password+OTP profile
- Sample lockout alert and unlock ticket for a privileged account
Environment
Cloud IdP primary; VPN for lab; ~180 users.Tools
Discussion(0)
No discussion on this control yet
Edge cases, scoping questions, and “would this pass?” scenarios belong here.
Sign in to start a thread.