Ensure the Login Failure and/or Inactivity check boxes are selected. Use the fields in this section to set the parameters based on which a user account would be locked:
Field | Description |
|---|---|
Number of Consecutive Login Failures | Set the maximum number of unsuccessful login attempts to 3. |
Prevent Login For | Set the duration of lock out field between 1 and 1440 minutes. |
Lock Inactive Users After | Set the number of days to lock the inactive users between 1 and 180 days.
|
After selecting the required parameters, any new user created henceforth will comply with the password policy enabled. The password policy can be enabled only at the root admin domain level.
Note
The local administrator cannot be locked out to ensure that administrative access is always maintained.
Customize the unlock time and maximum authentication attempts
To customize the amount of time to unlock a locked out account in the Manager, go to the Manager shell and modify the unlock time in unlock_time=<value in seconds> within the files /etc/pam.d/system-auth and /etc/pam.d/password-auth.
To customize the maximum number of authentication attempts permitted per connection in the Sensor, go to the Sensor shell and modify the value in MaxAuthTries=<value> within the /etc/ssh/sshd_config file.