Logo Questions Linux Laravel Mysql Ubuntu Git Menu
 

Does B2C Lock An Account After N Failed Attempts?

Tags:

azure-ad-b2c

How does B2C handle this situation? I couldn't find anything on docs.microsoft.com

like image 456
spottedmahn Avatar asked Aug 31 '17 12:08

spottedmahn


1 Answers

Azure AD B2C does provide password lockout. The logic and duration is not a straight forward, "lock out X minutes with exponential cooldown after Y wrong password attempts." There's an intelligent and evolving algorithm that considers many other signals to disambiguate between bad actors and mistakes and other benign scenarios.

Read more about in the Azure AD B2C Threat Management documentation

like image 169
Saca Avatar answered Oct 20 '22 17:10

Saca