What is Smart lockout?
If you can't get into Atlas, you're most likely temporarily locked out by Smart lockout — a security feature that protects accounts from unauthorised access by automatically detecting and blocking suspicious login attempts, such as brute-force attacks or credential stuffing.
It analyses login behaviour and patterns in real time, so it can tell the difference between legitimate users and potential attackers. Genuine users keep accessing their accounts, while threats are blocked automatically.
How it works
Lockout is triggered after 3 failed login attempts.
The lockout period is 60 seconds for the first 10 lockouts. After that, the duration increases after every 10 lockout periods, up to a maximum of 5 hours.
The lockout counter resets to zero after a successful login when the account isn't locked.
During a lockout, the account can't be accessed even with the correct password until the lockout expires.
Note: Similar passwords (for example, Password123! and Password124!) are treated as a single failed attempt to minimise false lockouts.
What you'll experience during a lockout
First and second attempts: you're simply told the credentials are invalid.
Third failed attempt: Smart lockout triggers, the account is temporarily locked for 60 seconds, and you see an error message.
During the lockout: the account can't be accessed, even with the correct password, until the lockout expires.
How to fix it
The right steps depend on your role — open the section that applies to you.
If you're a learner
If you're a learner
A lockout is a protective measure, not a fault with your account. To get back in:
Wait a full minute before trying again, and avoid repeated guesses — each failed attempt can extend the lockout.
Reset your password if you're unsure of it, rather than keep guessing. See How do I reset my password?
If you log in with a username (no email), you can't reset it yourself — ask your training administrator to reset it for you.
If a reset or login email doesn't arrive, check your spam folder. See I am not getting emails, what should I do?
If you're an administrator
If you're an administrator
When a user comes to you locked out:
Reassure them: this is a security measure working as intended, not an error.
Advise them to wait: a minute between attempts, for up to 10 lockout periods. Repeated attempts prolong the lockout.
Help with passwords:
Email users — direct them to the password reset on the login page.
Username (no-email) users — reset their password for them once you've confirmed their identity.
If a legitimate user stays locked out with the correct password, or you see signs of malicious access, see When should I contact support about a lockout?
FAQ
Can I disable Smart lockout?
Can I disable Smart lockout?
No. Smart lockout can't be disabled — it protects every account.
Can I unlock my account immediately?
Can I unlock my account immediately?
No. The account stays locked until the lockout duration expires automatically, unless support manually resets it in a genuine case.
How does Smart lockout tell attackers apart from legitimate users?
How does Smart lockout tell attackers apart from legitimate users?
It evaluates IP reputation, login behaviour, and password entry patterns to distinguish genuine login attempts from malicious activity.
Can the lockout duration be adjusted?
Can the lockout duration be adjusted?
Yes, but only by support. See When should I contact support about a lockout?
What if I keep getting locked out even with the correct password?
What if I keep getting locked out even with the correct password?
This is one of the few cases to contact support. See When should I contact support about a lockout?
