Configure Account Lockout Policy
Turn on Account Lockout Policy with the Azion API and set how many failed sign-in attempts lock a user, and for how long.
You can turn on Account Lockout Policy through the Azion API. The policy blocks a user who reaches the maximum number of failed sign-in attempts, and that user cannot try again until the blocking period ends. To release a user before the period ends, refer to Unlock a user from Account Lockout Policy. If your own user is the one locked out, refer to Troubleshoot Azion Console sign-in.
Prerequisites
- Account Owner privileges. A request from any other user returns Error 403, and so does a request on an account that does not have the policy activated.
- An account with Enterprise or Mission-Critical Support, which includes the policy by default. For the support tiers, refer to Support guidelines.
- A personal token for the
Authorizationheader. To create one, refer to Manage personal tokens.
The policy an organization sets applies to every account level under it.
Read the current policy
The policy is inactive on an account until you change it. Read its status before you update it.
Send a GET request to the auth/policies/lockout endpoint:
The response is similar to this one:
The active key reports whether the policy is on for the account.
Turn on the policy
The request body sets three keys:
| Key | Type | Description |
|---|---|---|
active | Boolean | Status of the policy. Accepted values: true and false. Default value: false |
max_attempts | Integer | Maximum number of failed attempts before the lockout. Default value: 3 |
blocking_period | Integer | Time a user account stays locked after it reaches the maximum number of failed sign-in attempts. The user cannot try to sign in during this time. Default value: 1440, which is 24 hours in minutes |
Send a PUT request to the auth/policies/lockout endpoint:
The response is similar to this one:
The policy is active on the account. A user who exceeds max_attempts failed sign-in attempts stays blocked for the blocking_period. To check the stored values, send the GET request from Read the current policy again.
For every endpoint the API exposes, refer to the Azion API reference.