Skip to content
Skip to main content
Logs, Records & Provider Evidence Technical Explainer

What is an account-lockout event?

An account-lockout event records a policy preventing further authentication, commonly after a threshold of failures. It establishes restriction of access, not why all the triggering attempts occurred.

Ordinary and hostile activity can reach the same threshold

A forgotten password, a device storing an old credential, an unattended service or an attacker testing passwords may all cause repeated rejection. With shared accounts, several systems can contribute to one lockout.

The event may record the target account, policy, reason, final source and time. Some products expose only the last triggering attempt, so that address should not automatically be assigned to the entire sequence.

Read the lockout with its policy and failures

Obtain the failure threshold, measurement period, reason codes and unlock behaviour. Preserve preceding attempts, later successes, devices and administrator actions. Patterns across accounts, sources and time can separate a stale service credential from broader password testing.

Do not infer the account holder's presence or an attack from the lockout alone. State the policy outcome, then explain the evidence supporting the identified cause.

The point to remember

A lockout proves a security threshold was reached; surrounding attempts and policy details explain how.

Reference: LOG-096Logs, Records & Provider Evidence