Password Lockout Examples
The following examples illustrate how the Cloud Access Service CAS password lockout works.
In all examples, the administrators has configured 4 unsuccessful password attempts before lockout and a lockout duration of 30 minutes.
Four Unsuccessful Password Attempts
Time in Minutes | User Activity |
|---|---|
00:00 | User1 has first unsuccessful password attempt. |
00:01 | User1 has second unsuccessful password attempt. |
00:02 | User1 has third unsuccessful password attempt. |
00:03 | User1 has fourth unsuccessful password attempt. CAS locks the password method for this user for 30 minutes. |
00:25 | User1 submits a password attempt (either with correct or incorrect password). CAS ignores the request because the method is locked. |
00:33 | CAS unlocks the password method for the user and resets the number of unsuccessful password attempts. |
00:56 | User1 completes password authentication. |
Two Unsuccessful Password Attempts and One Successful Attempt
Time in Minutes | User Activity |
|---|---|
00:00 | User1 has first unsuccessful password attempt. |
00:01 | User1 has second unsuccessful password attempt. |
00:02 | User1 completes password authentication. CAS resets the number of unsuccessful password attempts. |
CAS Resets Unsuccessful Attempts
Time in Minutes | User Activity |
|---|---|
00:00 | User1 has first unsuccessful password attempt. |
00:15 | User1 has second unsuccessful password attempt. |
00:29 | User1 has third unsuccessful password attempt. |
00:59 | CAS resets the number of unsuccessful password attempts. |
01:00 | User1 has first unsuccessful password attempt. |
01:02 | User1 completes password authentication. |
Related Articles
Access Manager 6.1 - aserver reports passwords are expired when password policy shows them as valid. 13Number of Views Token Policy User PIN Complexity 39Number of Views Self-Service Troubleshooting Policy 24Number of Views Password Policy 123Number of Views Lockout Policy 88Number of Views
Trending Articles
Downloading RSA Authentication Manager license files or RSA Software token seed records RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory Mandatory Certificate Upgrade Required by 6th October 2025 for RSA MFA Agent for PAM, RSA MFA Agent for Apache, and Third … RSA Authentication Manager 8.9 Release Notes (January 2026)