Account lockout
Lock user accounts after consecutive failed login attempts, with settings for the lock duration, number of failed attempts that trigger a lock, and a multiplying factor that extends the lock time for repeat offenses.
Configure account lockout
Configure the account lockout behavior on the OneWelcome Identity Platform console.
If you prefer to use an API instead of the console, you can find the account lockout settings in the Credential API
-
Log in to your OneWelcome Identity Platform and select your tenant, if required.
-
On the OneWelcome Identity Platform configuration console, select Core > Account lockout.
The Maximum idle time and Maximum lockout active values are configured globally and are not editable. The Maximum idle time is the maximum amount of time that you can enter for the Lockout time. The Maximum lockout active indicates whether this maximum is in use.
-
Under Global settings, select the Account lockout active option:
-
To turn on the account lockout feature, select Yes.
-
To turn off the account lockout feature, select No.
-
-
Enter the Maximum failed attempts, which is the maximum number of consecutive failed login attempts. When the user reaches this maximum, their account is locked. The maximum number of failed attempts should be from 1 to 10.
-
Enter the Lockout time (In minutes), which is the number of minutes that an account is locked for. After the lockout time ends, the user can try to log in again. The lockout time should be from 1 to 60 minutes.
-
Enter the Lockout time multiplier, which is the multiplying factor that the system uses to increase the locking duration for each successive account lockout. The multiplier should be from 2 to 10.
For example, if the user is locked for Lockout time (In minutes), and after that amount of time they try again for a number of attempts equal to the Maximum failed attempts, the account is locked for Lockout time (In minutes) * Lockout time multiplier.
-
In the Applies to authentication methods, select the authentication methods. You can select multiple. Users have an unlimited number of login attempts using any authentication methods that you don't select.
Add brand overrides
You can override the global settings for each brand in your tenant.
-
Under Brand overrides, select Add brand, and then select the brand. The brand settings override the Global settings.
-
Configure the account lockout settings for the brand.
-
Add more brand overrides, as needed.
-
Select Save.
Delete brand overrides
-
Under Brand overrides, find the brand that you want to delete.
-
Next to the brand name, select the delete icon.
The brand and its overrides are deleted.