Unlocking user behavior and customization

If user gets locked due to multiple failed login attempts, what is the default timeout to get thyself unlocked? Is it configurable? Is there self service to get unlocked by another user in the same organization?

In Brute-force Protection of Attack Protection no such configuration is available. Is there any other place?

Hi @Vijay.Mohite,

Welcome to the Auth0 Community!

To answer your specific questions regarding Brute-force Protection:

  • The default timeout is 30 days from the last failed login attempt. This duration is a fixed system limit and is not configurable. Note that each new failed attempt resets this 30-day window.
  • There is no current feature for a standard user to unlock another. Unlocking must be performed by a Tenant Administrator or by the affected user themselves.

How a user can be unblocked:

  1. Administrator Action: An admin can remove the block via the Auth0 Dashboard (User profile) or the Management API.
  2. User Self-Service: The user can click the unblock link in the Blocked Account Email (if you have this enabled) or by successfully completing a Password Reset.
  3. Threshold Adjustment: While the 30-day duration isn’t configurable, the Maximum Attempts (the threshold that triggers the block) can be adjusted in Security > Attack Protection > Brute-force Protection.

This options are also described in the following article - Error “Your Account has been Blocked After Multiple Consecutive Login Attempts”, which contains a video explanation as well.

Customization: If you want to guide users on how to unblock themselves, you can Customize the Error Message they see on the login screen or customize the Blocked Account Email template.

As you noted, since the timeout duration itself is not configurable, I recommend creating a Product Feedback request if this is a requirement for you, since others might be interested in such a feature as well and get updated for possible future implementations.

I hope this helps!
Thank you,
Remus

Thank you and appreciate it. This is much helpful.

Regards!

1 Like

Hi @Vijay.Mohite,

I am glad this helps!
Have a great one,
Remus