Machine Account Lockout Threshold

๐Ÿ”’ Secure Bits ๐Ÿ’ก
๐——๐—ถ๐—ฑ ๐˜†๐—ผ๐˜‚ ๐—ธ๐—ป๐—ผ๐˜„ you can enforce lockout โ€” ๐—ฒ๐˜ƒ๐—ฒ๐—ป ๐˜„๐—ต๐—ฒ๐—ป ๐—ฎ ๐—ฑ๐—ฒ๐˜ƒ๐—ถ๐—ฐ๐—ฒ ๐—ถ๐˜€ โ€œ๐—ผ๐—ณ๐—ณ๐—น๐—ถ๐—ป๐—ฒโ€?

Normally, Windows relies on domain controllers and ๐—•๐—ฎ๐—ฑ๐—ฃ๐˜„๐—ฑ๐—–๐—ผ๐˜‚๐—ป๐˜ to enforce account lockouts. But if a ๐—ฑ๐—ฒ๐˜ƒ๐—ถ๐—ฐ๐—ฒ ๐—ถ๐˜€ ๐—ผ๐—ณ๐—ณ๐—น๐—ถ๐—ป๐—ฒ (no line of sight to DCs), an attacker ๐—ฐ๐—ผ๐˜‚๐—น๐—ฑ ๐—ฏ๐—ฟ๐˜‚๐˜๐—ฒ-๐—ณ๐—ผ๐—ฟ๐—ฐ๐—ฒ cached credentials without triggering traditional lockout policies.

This is where a not well known configuration comes in:
๐Ÿ›ก๏ธ ๐— ๐—ฎ๐—ฐ๐—ต๐—ถ๐—ป๐—ฒ ๐—”๐—ฐ๐—ฐ๐—ผ๐˜‚๐—ป๐˜ ๐—Ÿ๐—ผ๐—ฐ๐—ธ๐—ผ๐˜‚๐˜ ๐—ง๐—ต๐—ฟ๐—ฒ๐˜€๐—ต๐—ผ๐—น๐—ฑ

โœ… With this setting, Windows enforces a lockout even without DC access.
๐Ÿ” If ๐—•๐—ถ๐˜๐—Ÿ๐—ผ๐—ฐ๐—ธ๐—ฒ๐—ฟ is enabled, it triggers a ๐—ณ๐˜‚๐—น๐—น ๐—ฑ๐—ฒ๐˜ƒ๐—ถ๐—ฐ๐—ฒ ๐—น๐—ผ๐—ฐ๐—ธ๐—ผ๐˜‚๐˜ and requires the 48-digit recovery key.
๐Ÿ” Without BitLocker, it simply reboots the machine โ€” a speed bump at best.

Windows already slows down failed logons over time. Only ๐—•๐—ถ๐˜๐—Ÿ๐—ผ๐—ฐ๐—ธ๐—ฒ๐—ฟ-๐—ฏ๐—ฎ๐˜€๐—ฒ๐—ฑย lockout truly raises the bar.

๐—œ ๐—ฐ๐—ฎ๐—ป ๐—ถ๐—บ๐—ฎ๐—ด๐—ถ๐—ป๐—ฒ ๐˜๐˜„๐—ผ ๐—ฟ๐—ฒ๐—น๐—ฒ๐˜ƒ๐—ฎ๐—ป๐˜ ๐—ฎ๐˜๐˜๐—ฎ๐—ฐ๐—ธ ๐˜€๐—ฐ๐—ฒ๐—ป๐—ฎ๐—ฟ๐—ถ๐—ผ๐˜€:
1๏ธโƒฃ Device left unattended or stolen โ€” attacker tries passwords at login screen.
2๏ธโƒฃ Device stolen and BitLocker is only TPM-based โ€” brute-force attempts still possible.

Recommendation is to configure this GPO ๐—ฎ๐—ฏ๐—ผ๐˜ƒ๐—ฒ ๐˜†๐—ผ๐˜‚๐—ฟ ๐˜€๐˜๐—ฎ๐—ป๐—ฑ๐—ฎ๐—ฟ๐—ฑ ๐—”๐—— ๐—น๐—ผ๐—ฐ๐—ธ๐—ผ๐˜‚๐˜ย policy. If AD lockout is 10 attempts, set this to 15.

๐Ÿ“ย ๐—š๐—ฃ๐—ข ๐—ฃ๐—ฎ๐˜๐—ต:
Computer Configuration > Windows Settings > Security Settings > Local Policies > Security Options > Interactive logon: Machine account lockout threshold

Have you used this setting before? Do you see a need for it in your organization?