What is Smart lockout?
Smart lockout is a security feature that protects user accounts from unauthorised access by automatically detecting and blocking suspicious login attempts, such as brute-force attacks or credential stuffing.
It works by analysing login behaviour and patterns in real time, so it can intelligently tell the difference between legitimate users and potential attackers. This helps ensure genuine users can keep accessing their accounts, while threats are blocked automatically.
How it works
Lockout is triggered after 3 failed login attempts.
The lockout period is 60 seconds for the first 10 lockouts. The next lockout periods are slightly longer and increase in duration after every 10 lockout periods, the longest eventually being 5 hours.
The lockout counter resets to zero after a successful login when the account isn't locked.
Note: Similar passwords (for example, Password123! and Password124!) are treated as a single failed attempt to minimise false lockouts.
What users will experience
First and second attempts: the user is simply notified of invalid credentials.
Third failed attempt: Smart lockout triggers after the third consecutive failure. The user is temporarily locked out for 60 seconds and receives an error message.
During lockout: the account can't be accessed, even with the correct password. The lockout expires after the set duration unless it's manually reset — see the FAQ below for who can do this.
Guidance for supporting users
Reassure: this is a protective measure, not an error.
Advise: users should wait 1 minute before retrying, for up to 10 lockout periods. If the password is forgotten:
Email users: direct them to the password reset on the login page.
No-email users: guide them to request a password reset from their Service Owner, or validate and reset it manually if their identity is confirmed.
Avoid: suggesting repeated attempts, as this prolongs the lockout duration.
When to escalate to Technical Support
Escalate if:
A legitimate user remains locked out despite entering the correct credentials, and resetting the password hasn't resolved the issue.
There are clear signs of malicious access attempts.
FAQ
Can the lockout duration be adjusted?
Can the lockout duration be adjusted?
Yes. Contact [email protected] for support.
Can users unlock their accounts immediately?
Can users unlock their accounts immediately?
No. Users must wait until the lockout duration expires automatically, unless it's manually reset.
Can support manually unlock user accounts?
Can support manually unlock user accounts?
Yes, but this should be reserved for cases where users face repeated lockouts despite correct login attempts. Contact [email protected] for support.
What if a user keeps getting locked out even with the correct password?
What if a user keeps getting locked out even with the correct password?
Escalate these cases to Technical Support.
How does Smart lockout identify attackers versus legitimate users?
How does Smart lockout identify attackers versus legitimate users?
Smart lockout evaluates IP reputation, login behaviour, and password entry patterns to tell genuine login attempts apart from malicious activity.
Can I disable Smart lockout?
Can I disable Smart lockout?
No, it can't be disabled.
What happens if users get locked out outside support business hours?
What happens if users get locked out outside support business hours?
Users must wait until the lockout duration expires automatically and try logging in again, or wait until we can support them during business hours.
