Enforce automatic device lockout following a predetermined threshold of local failed authentication
attempts on portable end-user devices, where supported. For laptops, do not allow more than 20
failed authentication attempts; for tablets and smartphones, no more than 10 failed authentication
attempts. Example implementations include Microsoft® InTune Device Lock and Apple® Configuration
Profile maxFailedAttempts.
To enforce automatic device lockout on portable end-user devices after a predetermined number of failed authentication attempts, the organization adopts several strategies. For laptops, the strategy involves reviewing password practices to implement a limit of 20 failed attempts before lockout. For tablets and smartphones, security policies are set to lock devices after 10 failed attempts. The implementation is supported by mobile device management (MDM) solutions, which enforce these security policies across devices.
To protect from e.g brute force attacks the organisation must use at least one of the following practices:
In addition the following password practices should be in place: