Account Lockout Threshold Not Working



On my DC, in Domain Security Policy... In Windows
Settings, Security Settings, Account Policies, the
Account Lockout Threshold is set for 5 invalid attempts.
I set this myself about a year ago but never tested it.
Just found out from a user and proved it myself that the
lockout occurs at 3 bad attempts. Am I setting this in
the wrong place? Any help / much appreciated!
Thanks! -=gu=-

Steven L Umbach

Domain level is where that policy needs to be configured. You can run "net accounts"
on a domain controller to see what the threshold is. What may have happened is that
the operating system often interprets one bad logon attempt by the user as multiple
logon failures. That is one reason why MS recommends 10 as the lockout threshold
assuming users need to use reasonably secure passwords. The links below may be
helpful. --- Steve

