Windows Enables Account Lockouts After Certain Failed Access Attempts

Windows

To protect Windows systems against brute force attacks, Microsoft is automatically enabling the account lockout of user accounts after a certain number of failed access attempts.

This has been by default on Windows 11 for a couple of months and now it’s coming to all Windows versions that have the October cumulative update installed. Aside from this, Microsoft is also mandating the use of strong and complex passwords for local admin accounts on the system.

Account Lockouts After Failed Login

One of the common vectors that threat actors use to access their targets’ Windows systems is brute force attack – where they rub a list of possible passwords against the login fields to match the actual password and gain access.

To prevent this, Microsoft enabled the automatic account (including the admin’s) lockout in Windows 11 after a certain number of failed attempts to log in. The policy was introduced in July this year, where the user accounts are locked out for 10 minutes after 10 failed sign-in attempts within 10 minutes.

Announcing this move, Microsoft’s VP for Enterprise and OS Security, David Weston, said, “This technique is very commonly used in Human Operated Ransomware and other attacks – this control will make brute forcing much harder, which is awesome!”

And now, three months after his announcement, Microsoft is bringing this policy to all the Windows versions that have the October cumulative update installed. System admins can find this option of “Allow Administrator account lockout” under the Local Computer Policy\Computer Configuration\Windows Settings\Security Settings\Account Policies\Account Lockout Policies.

This group policy will be enabled by default on all the Windows 11 22H2 machines and others having the October 2022 Windows cumulative updates installed, as mentioned above. Aside from this, Microsoft is also mandating the use of complex passwords for local accounts that “must have at least three of the four basic character types (lower case, upper case, numbers, and symbols).”

All these are to reduce the attacking surface for hackers, who may perform various malicious operations after gaining access to the targeted system.

Other Trending News:-  News

Total
0
Shares
Leave a Reply

Your email address will not be published. Required fields are marked *

Previous Post
COVID-19 Themed Phishing Campaign is Abusing Google Forms

COVID-19 Themed Phishing Campaign is Abusing Google Forms

Next Post
Netflix

Netflix to launch cheap ad-supported plan in November

Related Posts