The right thresholds balance security (catch attacks early) with usability (don't lock out fat-fingered users repeatedly). This article shares the levers and recipes by audience.
Default Recipe
- Attempts: 5
- Monitoring period: 15 minutes
- Ban duration: 30 minutes
- Email user on lockout: Yes
Tightening Recipes
- Admin accounts only: Attempts 3, monitoring 60 minutes, ban 24 hours, require manual unblock. These accounts shouldn't be brute-forced under any circumstances.
- Financial services: Attempts 4, monitoring 30 minutes, ban 1 hour. Include passkey enforcement.
Loosening Recipes
- Public consumer app: Attempts 8, monitoring 30 minutes, ban 15 minutes. Most users will mistype before remembering or hitting reset.
- B2B with password-manager users: Attempts 6, monitoring 10 minutes, ban 30 minutes. Users either know their password or use the manager; few mistakes.
Combining Account + IP
Set IP attempts higher than account attempts. Reason: a single user hitting their account ban shouldn't also burn the IP ban — they have legitimate reason to try again later.
Worked Examples
- Healthcare admin portal: 3 attempts, 60 min monitoring, 24 hr ban with manual review.
- Consumer marketplace: 8 attempts, 30 min monitoring, 15 min ban — generous but enough to deter automation.
- API user accounts: 10 attempts on the auth endpoint, 5 min window, 30 min ban — handles bursty mistakes from misconfigured integrations.