Edit online

Account Lockout After Failed Log-in Attempts

Details about what happens after repeated failed log-in attempts, how long account lockout lasts, and which authentication methods are affected.

After a maximum number of consecutive failed log in attempts (default is 5), your account is temporarily locked for a period (default is 30 minutes). During the lockout period, logging in is rejected even with the correct password. The interface displays a message such as: Too many failed attempts. Retry after X minutes (the number of minutes is provided by the server). The lockout expires automatically so you just need to wait before trying again. A successful log in before reaching the limit resets the failed-attempt counter.

Attention:
This applies only to email and password log in. Logging in with Google, GitHub, or OIDC is not affected by account lockout.
Note:
For the Oxygen Content Fusion Enterprise Server, the number of attempts and lockout duration can be configured by the administrator. See Account Lockout.