A brief look at configuring Account Lockout Policy setting
A malicious insider who attempts to use a trial and error method to try various password combinations to try to log on to your system. Windows domain controllers respond to such potential attacks by keeping track of logon attempts. In such cases, you can configure the DC to disable a user account for a preset time period using the Account Lockout Policy settings.
You can confiture the Account Lockout Policy settings by navigating to Computer Configuration>Policies>Windows Settings>Security Settings>Account Policies>Account Lockout Policy in the Group Policy Management Console.
The following is a list from Microsoft documentation policy setting's implementation and best practices considerations, policy location, default values for the server type or Group Policy Object (GPO), relevant differences in operating system versions, and security considerations (including the possible vulnerabilities of each policy setting), countermeasures that you can implement, and the potential impact of implementing the countermeasures.
| Topic | Description |
|---|---|
| Account lockout threshold | Describes the best practices, location, values, and security considerations for the Account lockout threshold security policy setting. |
| Account lockout duration | Describes the best practices, location, values, and security considerations for the Account lockout duration security policy setting. |
| Reset account lockout counter after | Describes the best practices, location, values, and security considerations for the Reset account lockout counter after security policy setting. |
About ADAudit Plus
ADAudit Plus is a real time change auditing software that helps keep your Active Directory, Azure AD, Windows file servers, NetApp filers, EMC file systems, Synology file systems, Windows member servers, and workstations secure and compliant. With ADAudit Plus, you can get visibility into:
- Authorized and unauthorized AD management changes
- User logons, logoffs, and account lockouts
- GPO changes
- Group attribute and membership changes
- OU changes
- Privileged access and permission changes
- Azure AD logons, and changes to roles, groups, and applications
- PowerShell scripts and modules
among other things.
There are more than 200 event-specific reports, and you can configure instant email alerts. You can also export the reports to XLS, HTML, PDF and CSV formats to assist in interpretation and forensics. For more information on ADAudit Plus, visit: https://www.manageengine.com/active-directory-audit/.
Explore Active Directory auditing and reporting with ADAudit Plus.
- Related Products
- ADManager Plus Active Directory Management & Reporting
- ADAudit Plus Real-time Active Directory Auditing and UBA
- EventLog Analyzer Real-time Log Analysis & Reporting
- ADSelfService Plus Self-Service Password Management
- AD360 Integrated Identity & Access Management
- Log360 (On-Premise | Cloud) Comprehensive SIEM and UEBA
- AD Free Tools Active Directory FREE Tools
