RapidIdentity protects user accounts against account takeover attacks by automatically locking the account after five unsuccessful authentication attempts in 5 minutes. A locked account requires a delegate, such as a teacher, manager, or administrator, to unlock it.
The account lockout policy is configured on a password policy in RapidIdentity, but it applies to authentication attempts in general, not just password authentications. All RapidIdentity systems have a default password policy that includes a default account lockout policy. The policy applies to all users that are not associated with an administrator-defined password policy.
When a user is associated with more than one password policy, RapidIdentity applies the most restrictive policy. The same is true for authentication policies. However, authentication policies do not apply to the authentications created by the single sign-on extension with Seamless Learning Access.
Access to your RapidIdentity administrator portal
The account lockout policy applies to all users associated with the password policy.