Configuring user account lockout settings
Configure settings to lock user accounts based on too many failed authentication attempts.
Steps
-
Edit the
<pf_install>/pingfederate/server/default/data/config-store/com.pingidentity.common.security.AccountLockingService.xmlfile.The following table provides more information about the file properties.
If you’re running PingFederate in a clustered environment, edit this file on the console node.
Property Description MaxConsecutiveFailuresThe maximum number of failed attempts before a user is locked out for a time period.
The default value is
3.The per instance setting in the HTML Form Adapter and the Username Token Processor overrides this property.
LockoutPeriodThe amount of time in minutes that a user is locked out when the
MaxConsecutiveFailuresthreshold is reached.The default value is
1minute. -
Save the change.
-
Restart PingFederate.
-
If you’re running PingFederate in a clustered environment, click Replicate Configuration in System > Server > Cluster Management.