Educause Security Discussion mailing list archives

Brute force credentials protection


From: Mike Dronen <mike.dronen () MINNETONKASCHOOLS ORG>
Date: Mon, 4 Mar 2019 13:03:50 -0700

All - Looks like it's been a while since this topic has come up in the forum. I'm wondering how you protect against 
brute force password attempts, i.e. two-factor auth. In our environment we set an attribute in AD to lock the user 
account for a prescribed period of time after four failed attempts. This appears to work for us. Just wondering if 
there are other mechanisms just as good or better? Thanks.


Current thread: