Lock out policy for Domain users on 2008 Window Server.

How do you lock out a user when the user has failed three times entering his or her password.  And would only allow the user to log back in after 5 minutes.  Thank you in advance.
Victor_TorresAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

MrSlithyCommented:
You need to set up a group policy for lockout procedure on the windows 2008 server click on the start menu, administrative tools, group policy management. In the consul tree expand the forest and then the domains select the domain that you're referring to. Double-click on the Divit Maine to reveal the GPO's links to that domain.

You're looking for a GPO that's name default domain policy once you find it select edit. When the editor opens up you want to navigate to computer configuration, policies, Windows settings, security settings, account policies, account lockout policy.

When you double-click on the lockout policy it shows you different account lockout settings available. Right click on any of them and you'll be able to ship the properties.

This is assuming that you kind of know your way around group policy and what do you set it or not you do have a domain to full policy set up. However I don't think three times would be good. It sometimes takes two or three times for somebody realizes that their password is not right because of Locks are numb locks or something like that.  I would go higher than that. It's for his time before they can retry again standards are usually anywhere from 15 to 30 minutes. But I don't have an opinion on that.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
MrSlithyCommented:
I miss spoke regarding 15 to 30 minutes being a standard. I don't know that for sure.
0
Toni UranjekConsultant/TrainerCommented:
Why would you want to lock out users after three failed attempts?

Lock out policy should prevent online attack from hackers, not irritate users and administrators.

Check out templates in Security Compliance Toolkit from Microsoft:
http://go.microsoft.com/fwlink/?LinkId=182512
0
David Johnson, CD, MVPOwnerCommented:
You want a lock out policy for all because a user may know the login name but not the password and it slows down password attempts. You adjust the settings depending upon your environment. There should be a clear cut policy for this in which both management and IT is happy with it. Remember that IT only offers services to the company and management is still in charge of the company
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Active Directory

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.