---
name: azion-check-account-lockout-policy-logs
description: >-
  Call the Account Lockout Policy endpoint to read which accounts the policy locked, when each lock started, and when it ends.
---

# Check Account Lockout Policy logs

You can read the records Account Lockout Policy writes by sending a `GET` request to the Azion API. The records carry the failed login attempts and the account lockouts on your account, so you can monitor security events and act on them.

The request below carries a placeholder for the token. Replace it with a personal token from your own account.

---

## Prerequisites

- *Account Owner* privileges on the account. Account Lockout Policy requires them to configure the policy and to read the records it writes.
- A personal token. To create one, refer to [Personal Tokens](/en/documentation/fundamentals/personal-tokens/).

---

## Configure the policy

[Account Lockout Policy](/en/documentation/fundamentals/account-lockout-policy/) records a failed login attempt or a lockout only on an account that has the policy activated. A request against an account without the policy activated returns `Error 403`. A request sent without *Account Owner* privileges returns the same status.

To activate the policy, refer to [Configure Account Lockout Policy](/en/documentation/guides/application-security/access-and-compliance/configure-account-lockout-policy/).

---

## Read the accounts the policy locked

The `locked` query parameter selects which set of user accounts the `identity/users` endpoint returns. `locked=true` returns the accounts the policy locked.

To retrieve the locked accounts:

```bash
curl --request GET \
  --url 'https://api.azion.com/v4/identity/users?locked=true' \
  --header 'Accept: application/json' \
  --header 'Authorization: Token [TOKEN VALUE]'
```

The response carries one entry per locked account:

```json
{
  "count": 2,
  "results": [
    {
      "id": 1,
      "lockout": {
        "locked_at": "20240101T10:20:01",
        "unlock_at": "20240102T10:20:01"
      }
    }
  ]
}
```

The keys the response carries:

| Key       | Type    | Description                                                                                                                              |
| --------- | ------- | ---------------------------------------------------------------------------------------------------------------------------------------- |
| `count`   | integer | Number of blocked user accounts. Example: `2`                                                                                            |
| `id`      | integer | Unique identifier of a user                                                                                                              |
| `lockout` | object  | Period during which the user account is blocked, with `locked_at` the timestamp the lockout starts and `unlock_at` the timestamp it ends |

Send the same request with `locked=false` to retrieve the user accounts the policy did not lock.

---

## Next steps

- [Activity History](/en/documentation/fundamentals/activity-history.md): The history of the activities performed on the account and by the users under it.
- [Personal Tokens](/en/documentation/fundamentals/personal-tokens.md): Create the token the Authorization header carries.
- [Real-Time Events](/en/documentation/platform/real-time-events.md): The event records Azion products write, in Azion Console and through a GraphQL API.
- [Account Lockout Policy](/en/documentation/fundamentals/account-lockout-policy.md): What the policy locks, when it unlocks, and the settings that govern both.
