Account lockout

Disabling an account or authenticator for a period, or until an administrator releases it, after too many consecutive failed logon attempts, to limit online password guessing.

Account lockout is a response to repeated failed authentication. NIST SP 800-53 Rev. 5 control AC-7 asks an organisation to set a limit on consecutive invalid logon attempts within a period and to choose what happens when it is exceeded: locking the account for a set time, locking it until an administrator releases it, delaying the next prompt, notifying an administrator, or another defined action. NIST SP 800-63B-4 section 3.2.2 frames the same idea as rate limiting, with an upper bound of 100 consecutive failures before the authenticator is disabled, and allows lower limits.

Lockout slows online guessing, but it creates an availability risk of its own: an attacker who knows usernames can lock out legitimate users on purpose, which is a form of denial of service. AC-7’s discussion notes that automatic lockouts are usually temporary for this reason. Lockout counts failures per account, so it does little against password spraying, or against credential stuffing, where the first attempt may already be correct. The threshold itself is an example of a clipping level.

Exam relevance: a scenario is likely to weigh lockout against availability. Candidates are expected to see that a strict permanent lockout can be turned into a denial-of-service tool, and that attacks spread across many accounts can stay below a per-account threshold.