Font Size:
Ask Joget AI

Lockout Mechanism

Introduction

The Password Lockout Mechanism in Joget is designed to protect user accounts from attacks by disabling the account after a certain number of failed login attempts. This feature enhances security by preventing unauthorized access through repeated password guesses.

How does it work?

The Lockout Mechanism is activated when a user enters an incorrect password a specified number of times. Once the threshold is reached, the account is locked, and the user is prevented from logging in. This policy prevents attackers from brute-forcing users' passwords.

To configure this mechanism, administrators can adjust settings in the Security Enhanced Directory Manager plugin.

Follow these steps to configure the Lockout Mechanism:

  1. Go to Settings > Directory Manager > Change Plugin.
  2. Click Security Enhanced Directory Manager.
  3. In the General section, set the number of Failed Login Attempts for Account Lockout.   
  4. Specify the Account Lockout Period (Minutes) (e.g., 10 minutes, 20 minutes, 30 minutes).
  5. After configuring the lockout parameters, click Submit to save the changes.
Created by Aadrian Last modified by Siti Noratiqah on Aug 27, 2026