Check Account Lockout Policy logs
Call the Account Lockout Policy endpoint to read which accounts the policy locked, when each lock started, and when it ends.
You can read the records Account Lockout Policy writes by sending a GET request to the Azion API. The records carry the failed login attempts and the account lockouts on your account, so you can monitor security events and act on them.
The request below carries a placeholder for the token. Replace it with a personal token from your own account.
Prerequisites
- Account Owner privileges on the account. Account Lockout Policy requires them to configure the policy and to read the records it writes.
- A personal token. To create one, refer to Personal Tokens.
Configure the policy
Account Lockout Policy records a failed login attempt or a lockout only on an account that has the policy activated. A request against an account without the policy activated returns Error 403. A request sent without Account Owner privileges returns the same status.
To activate the policy, refer to Configure Account Lockout Policy.
Read the accounts the policy locked
The locked query parameter selects which set of user accounts the identity/users endpoint returns. locked=true returns the accounts the policy locked.
To retrieve the locked accounts:
The response carries one entry per locked account:
The keys the response carries:
| Key | Type | Description |
|---|---|---|
count | integer | Number of blocked user accounts. Example: 2 |
id | integer | Unique identifier of a user |
lockout | object | Period during which the user account is blocked, with locked_at the timestamp the lockout starts and unlock_at the timestamp it ends |
Send the same request with locked=false to retrieve the user accounts the policy did not lock.