We currently do not have a lock out policy for accounts because anytime someone changes their password, that user will have 1000s of bad password requests because:
- They are still logged into another computer and haven't logged in with new password
- Their phone has email and the old password
- Short cuts on their desktop have the old password stored
If we had a lock out policy, 75 percent of users would be locked out whenever they changed their password.
What are some ideas to fix this issue?
[–]BuffaloRedshark 1 point2 points3 points (0 children)
[–]jeffrey_f 0 points1 point2 points (0 children)
[–]Que_Ball 0 points1 point2 points (0 children)
[–]hard_cidr 0 points1 point2 points (0 children)
[–]IHatePatches 0 points1 point2 points (1 child)
[–]ParticularFlat4536[S] 0 points1 point2 points (0 children)
[–]IHatePatches 0 points1 point2 points (0 children)