---
name: azion-configure-account-lockout-policy
description: >-
  Turn on Account Lockout Policy with the Azion API and set how many failed sign-in attempts lock a user, and for how long.
---

# Configure Account Lockout Policy

**Preview**

You can turn on [Account Lockout Policy](/en/documentation/fundamentals/account-lockout-policy/) through the Azion API. The policy blocks a user who reaches the maximum number of failed sign-in attempts, and that user cannot try again until the blocking period ends. To release a user before the period ends, refer to [Unlock a user from Account Lockout Policy](/en/documentation/guides/application-security/access-and-compliance/unlock-account-lockout-policy/). If your own user is the one locked out, refer to [Troubleshoot Azion Console sign-in](/en/documentation/support/account-access/).

---

## Prerequisites

- *Account Owner* privileges. A request from any other user returns *Error 403*, and so does a request on an account that does not have the policy activated.
- An account with **Enterprise** or **Mission-Critical** Support, which includes the policy by default. For the support tiers, refer to [Support guidelines](/en/documentation/support/).
- A personal token for the `Authorization` header. To create one, refer to [Manage personal tokens](/en/documentation/guides/platform/account-and-billing/personal-tokens/).

The policy an organization sets applies to every account level under it.

---

## Read the current policy

The policy is *inactive* on an account until you change it. Read its status before you update it.

Send a `GET` request to the `auth/policies/lockout` endpoint:

```bash
curl --request GET \
  --url https://api.azion.com/v4/auth/policies/lockout \
  --header 'Accept: application/json' \
  --header 'Authorization: Token [TOKEN VALUE]'
```

The response is similar to this one:

```json
{
  "data": {
    "active": false,
    "max_attempts": 1,
    "blocking_period": 0
  }
}
```

The `active` key reports whether the policy is on for the account.

---

## Turn on the policy

The request body sets three keys:

| Key               | Type    | Description                                                                                                                                                                                             |
| ----------------- | ------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `active`          | Boolean | Status of the policy. Accepted values: `true` and `false`. Default value: `false`                                                                                                                       |
| `max_attempts`    | Integer | Maximum number of failed attempts before the lockout. Default value: `3`                                                                                                                                |
| `blocking_period` | Integer | Time a user account stays locked after it reaches the maximum number of failed sign-in attempts. The user cannot try to sign in during this time. Default value: `1440`, which is *24 hours in minutes* |

Send a `PUT` request to the `auth/policies/lockout` endpoint:

```bash
curl --request PUT \
  --url https://api.azion.com/v4/auth/policies/lockout \
  --header 'Accept: application/json' \
  --header 'Authorization: Token [TOKEN VALUE]' \
  --header 'Content-Type: application/json' \
  --data '{
 	 "active": true,
  	"max_attempts": 1,
  	"blocking_period": 0
   }'
```

The response is similar to this one:

```json
{
  "state": "executed",
  "data": {
    "active": true,
    "max_attempts": 1,
    "blocking_period": 0
  }
}
```

The policy is active on the account. A user who exceeds `max_attempts` failed sign-in attempts stays blocked for the `blocking_period`. To check the stored values, send the `GET` request from [Read the current policy](#read-the-current-policy) again.

For every endpoint the API exposes, refer to the [Azion API reference](https://api.azion.com/).

---

## Next steps

- [Check Account Lockout Policy logs](/en/documentation/guides/application-security/access-and-compliance/account-lockout-policy-logs.md): List the users the policy locked and when each lock ends.
- [Unlock a user from Account Lockout Policy](/en/documentation/guides/application-security/access-and-compliance/unlock-account-lockout-policy.md): Release a locked user before the blocking period ends.
- [Configure User Session Timeout](/en/documentation/guides/application-security/access-and-compliance/configure-user-session-timeout.md): End idle and long-running sessions on the account.
- [Account Lockout Policy](/en/documentation/fundamentals/account-lockout-policy.md): Read what the policy locks and the settings that govern it.
