[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

255116

 
 

909

 
 

198683

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Reset account lockout counter after

ID: oval:org.secpod.oval:def:79716Date: (C)2022-05-07   (M)2023-07-14
Class: COMPLIANCEFamily: windows




This security setting determines the number of minutes that must elapse after a failed logon attempt before the failed logon attempt counter is reset to 0 bad logon attempts. The available range is 1 minute to 99,999 minutes. If an account lockout threshold is defined, this reset time must be less than or equal to the Account lockout duration. Default: None, because this policy setting only has meaning when an Account lockout threshold is specified. Counter Measure: Configure the Reset account lockout counter after setting to 15 minutes. Potential Impact: If you do not configure this policy setting or if the value is configured to an interval that is too long, a DoS attack could occur. An attacker could maliciously attempt to log on to each users account numerous times and lock out their accounts as described in the preceding paragraphs. If you do not configure the Reset account lockout counter after setting, administrators would have to manually unlock all accounts. If you configure this policy setting to a reasonable value the users would be locked out for some period, after which their accounts would unlock automatically. Be sure that you notify users of the values used for this policy setting so that they will wait for the lockout timer to expire before they call the help desk about their inability to log on. Fix: (1) GPO: Computer Configuration\Windows Settings\Security Settings\Account Policies\Account Lockout Policy\Reset account lockout counter after (2) REG: ### (3) WMI: root\rsop\computer#RSOP_SecuritySettingNumeric#Setting#KeyName=ResetLockoutCount And precedence=1

Platform:
Microsoft Windows 11
Reference:
CCE-96991-5
CPE    1
cpe:/o:microsoft:windows_11:21h2::x64
CCE    1
CCE-96991-5
XCCDF    3
xccdf_org.secpod_benchmark_general_Windows_11
xccdf_org.secpod_benchmark_NIST_800_53_r5_Windows_11
xccdf_org.secpod_benchmark_NIST_800_171_R2_Windows_11

© SecPod Technologies