ActiveManage Docs ← Back to activemanage.co.uk

Tuning Account Banning Thresholds

The right thresholds balance security (catch attacks early) with usability (don't lock out fat-fingered users repeatedly). This article shares the levers and recipes by audience.

Account banning configuration panel with Attempts (5), Monitoring period (15 min), Ban duration (30 min), and a toggle 'Email user on lockout'

Default Recipe

  • Attempts: 5
  • Monitoring period: 15 minutes
  • Ban duration: 30 minutes
  • Email user on lockout: Yes

Tightening Recipes

  • Admin accounts only: Attempts 3, monitoring 60 minutes, ban 24 hours, require manual unblock. These accounts shouldn't be brute-forced under any circumstances.
  • Financial services: Attempts 4, monitoring 30 minutes, ban 1 hour. Include passkey enforcement.

Loosening Recipes

  • Public consumer app: Attempts 8, monitoring 30 minutes, ban 15 minutes. Most users will mistype before remembering or hitting reset.
  • B2B with password-manager users: Attempts 6, monitoring 10 minutes, ban 30 minutes. Users either know their password or use the manager; few mistakes.

Combining Account + IP

Set IP attempts higher than account attempts. Reason: a single user hitting their account ban shouldn't also burn the IP ban — they have legitimate reason to try again later.

Worked Examples

  • Healthcare admin portal: 3 attempts, 60 min monitoring, 24 hr ban with manual review.
  • Consumer marketplace: 8 attempts, 30 min monitoring, 15 min ban — generous but enough to deter automation.
  • API user accounts: 10 attempts on the auth endpoint, 5 min window, 30 min ban — handles bursty mistakes from misconfigured integrations.