Item Search

NameAudit NamePluginCategory
1.1.1.1 Set 'Account lockout threshold' to '5 invalid logon attempt(s)'CIS Windows 8 L1 v1.0.0Windows

ACCESS CONTROL

1.2.1 Ensure 'Account lockout duration' is set to '15 or more minute(s)'CIS Windows 7 Workstation Level 1 v3.2.0Windows

ACCESS CONTROL

1.2.1 Ensure 'Account lockout duration' is set to '15 or more minute(s)'CIS Windows 7 Workstation Level 1 + Bitlocker v3.2.0Windows

ACCESS CONTROL

1.2.2 Ensure 'Account lockout threshold' is set to '10 or fewer invalid logon attempt(s), but not 0'CIS Windows 7 Workstation Level 1 + Bitlocker v3.2.0Windows

ACCESS CONTROL

2.20 Set 'Number of attempts allowed' to '10'CIS Microsoft Exchange Server 2013 CAS v1.1.0Windows

ACCESS CONTROL

3.6.1.11 OpenSSH: Ensure MaxAuthTries is set to 4 or lessCIS IBM AIX 7.1 L1 v2.1.0Unix

ACCESS CONTROL

4.4.2.1.1 Ensure pam_faillock module is enabledCIS CentOS Linux 7 v4.0.0 L1 WorkstationUnix

ACCESS CONTROL

5.2.1 Configure account lockout thresholdCIS Apple OSX 10.9 L1 v1.3.0Unix

ACCESS CONTROL

5.2.1 Configure account lockout thresholdCIS Apple OSX 10.11 El Capitan L1 v1.1.0Unix

ACCESS CONTROL

5.2.5 Ensure SSH MaxAuthTries is set to 4 or lessCIS Amazon Linux v2.1.0 L1Unix

ACCESS CONTROL

5.3.1 Ensure password creation requirements are configured - 'retry=3'CIS Ubuntu Linux 14.04 LTS Workstation L1 v2.1.0Unix

ACCESS CONTROL

5.3.2 Ensure lockout for failed password attempts is configured - password-auth 'auth [success=1 default=bad] pam_unix.so'CIS Amazon Linux v2.1.0 L1Unix

ACCESS CONTROL

5.3.2 Ensure lockout for failed password attempts is configured - password-auth 'auth sufficient pam_faillock.so authsucc audit deny=5 unlock_time=900'CIS Amazon Linux v2.1.0 L1Unix

ACCESS CONTROL

5.3.2 Ensure lockout for failed password attempts is configured - system-auth 'auth [default=die] pam_faillock.so authfail audit deny=5 unlock_time=900'CIS Amazon Linux v2.1.0 L1Unix

ACCESS CONTROL

5.3.2 Ensure lockout for failed password attempts is configured - system-auth 'auth required pam_faillock.so preauth audit silent deny=5 unlock_time=900'CIS Amazon Linux v2.1.0 L1Unix

ACCESS CONTROL

6.4 Limit Consecutive Login Attempts for SSH - MaxAuthTries = 3CIS Solaris 11 L1 v1.1.0Unix

ACCESS CONTROL

9.2.1 Set Password Creation Requirement Parameters Using pam_cracklib - retryCIS Debian Linux 7 L1 v1.0.0Unix

ACCESS CONTROL

Account lockout durationMSCT Windows 10 v21H1 v1.0.0Windows

ACCESS CONTROL

Account lockout durationMSCT Windows 10 v1507 v1.0.0Windows

ACCESS CONTROL

Account lockout durationMSCT Windows 10 1809 v1.0.0Windows

ACCESS CONTROL

Account lockout durationMSCT Windows Server v1909 DC v1.0.0Windows

ACCESS CONTROL

Account lockout durationMSCT Windows Server v1909 MS v1.0.0Windows

ACCESS CONTROL

Account lockout durationMSCT Windows Server 2012 R2 MS v1.0.0Windows

ACCESS CONTROL

Account lockout durationMSCT Windows Server 2016 DC v1.0.0Windows

ACCESS CONTROL

Account lockout thresholdMSCT Windows 10 v22H2 v1.0.0Windows

ACCESS CONTROL

Brocade - lockout duration set to 30 minutesTenable Best Practices Brocade FabricOSBrocade

ACCESS CONTROL

Brocade - lockout threshold set to 3Tenable Best Practices Brocade FabricOSBrocade

ACCESS CONTROL

Brocade - password warning must be set to at least 30 daysTenable Best Practices Brocade FabricOSBrocade

ACCESS CONTROL

Configuring a secure password policy for the BIG-IP system - Maximum Login FailuresTenable F5 BIG-IP Best Practice AuditF5

ACCESS CONTROL

Ensure 'aaa local authentication max failed attempts' is set to less than or equal to '3'Tenable Cisco Firepower Best Practices AuditCisco

ACCESS CONTROL

Ensure 'aaa local authentication max failed attempts' is set to your organization's poicyTenable Cisco Firepower Threat Defense Best Practices AuditCisco_Firepower

ACCESS CONTROL

ESXi : set-account-lockoutVMWare vSphere 6.5 Hardening GuideVMware

ACCESS CONTROL

Extreme : Password Policy - lockout-on-login-failuresTNS Extreme ExtremeXOS Best Practice AuditExtreme_ExtremeXOS

ACCESS CONTROL

FireEye - AAA lockout settings apply to the 'admin' userTNS FireEyeFireEye

ACCESS CONTROL

IBM i : Action When Sign-On Attempts Reached (QMAXSGNACN) - '3'IBM System i Security Reference for V7R3AS/400

ACCESS CONTROL

Interactive logon: Machine account lockout thresholdMSCT Windows 10 v21H1 v1.0.0Windows

ACCESS CONTROL

Interactive logon: Machine account lockout thresholdMSCT Windows 10 1809 v1.0.0Windows

ACCESS CONTROL

Interactive logon: Machine account lockout thresholdMSCT Windows 10 1903 v1.19.9Windows

ACCESS CONTROL

Interactive logon: Machine account lockout thresholdMSCT Windows Server v1909 MS v1.0.0Windows

ACCESS CONTROL

Interactive logon: Machine account lockout thresholdMSCT Windows Server v2004 MS v1.0.0Windows

ACCESS CONTROL

Interactive logon: Machine account lockout thresholdMSCT Windows Server v20H2 MS v1.0.0Windows

ACCESS CONTROL

Reset account lockout counter afterMSCT Windows 11 v1.0.0Windows

ACCESS CONTROL

Reset account lockout counter afterMSCT Windows Server 2025 DC v2506 v1.0.0Windows

ACCESS CONTROL

Reset account lockout counter afterMSCT Windows 10 1903 v1.19.9Windows

ACCESS CONTROL

Reset account lockout counter afterMSCT Windows Server v20H2 MS v1.0.0Windows

ACCESS CONTROL

Reset lockout counter afterMSCT Windows 10 v1507 v1.0.0Windows

ACCESS CONTROL

Salesforce.com : Setting Password Policies - 'invalid login attempts <= 5'TNS Salesforce Best Practices Audit v1.2.0Salesforce.com

ACCESS CONTROL

This security setting determines whether the builtin Administrator account is subject to account lockout policy - AllowAdministratorLockoutMSCT Windows Server 2025 DC v2506 v1.0.0Windows

ACCESS CONTROL

This security setting determines whether the builtin Administrator account is subject to account lockout policy - AllowAdministratorLockoutMSCT Windows Server 2025 DC v1.0.0Windows

ACCESS CONTROL

User Authentication Security - Configure login security options to hinder password guessing attacks - tries-before-disconnectJuniper Hardening JunOS 12 Devices ChecklistJuniper

ACCESS CONTROL