Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Excerpt
hiddentrue

Limit the number of failed login attempts, locking out the user for a certain period of time.


This Admin feature can be used to limit the number of failed login attempts, locking out the user for a certain period of time.Admin users can configure lockout settings for Website users. Maximum number of failed logins, maximum retry time, and the lockout period can be set.  If a user does not enter the correct password with the maximum failed login allowed, they will be locked out and cannot retry for a certain period. Admin users can unlock a locked user immediately in the CMS.

Image Added 



Step-by-step guide


To Set Login Retry Limitsset Lockout Settings:

  1. In the CMS, navigate go to Settings → Settings → General (on your website: /zSettings.aspx).
    In the section 'Login retry limits and lockouts' in Login maximum retry countFeature Management → User.

  2. Ensure User Accounts is toggled ON and click Configure.
    Image Added

  3. Scroll down to Lockout Settings.
    Image Added

  4. In Login Max Retry Count, enter the number of times a user can type an incorrect password before being locked out. Default: 3 times
    Image Removed; 0 = unlimited number of tries.

  5. In Login maximum retry timeMax Retry Time, enter the time period (in seconds) within which the number of failed login attempts are counted towards a lockout. Default: 0 = 60 seconds. 

  6. In Login failed login lockout timeFailed Lockout Time, enter the time period a user will be locked out for. Default: 0 = 30 seconds.

  7. When you have finished editing, click the Update button. Save or Save & Exit.


Unlock a Locked User

Admin users can unlock a locked user immediately. This will bypass the Failed Login Lockout Time set.


  1. Go to UsersWebsite Users.

  2. Use the Search tool to find the user. A locked user will have an 'Unlock' button in their row. 

    Image Added
  3. Click the Unlock button. The User will be unlocked immediately. NOTE - This Unlock button will display when the lockout period has passed and the user has not re-logged in. 

Related help

Content by Label
showLabelsfalse
max5
spacesKB
showSpacefalse
sortmodified
reversetrue
typepage
cqllabel in ("fail","login","user","retry","lockout") and type = "page" and space = "KB"
labelsuser login fail retry lockout