Skip to content
Authentication Reviewed 2026-09-13

Password Lockout Disabled

Scope and impact

Unrestricted authentication attempts can enable password guessing and credential stuffing. Account lockout is one possible control, not a universal requirement for every authentication design. Review rate limits, MFA, monitoring and recovery together. Random request-thread sleeps are not reliable throttling and can exhaust server capacity.

ASP.NET Core Identity example

These are alternative calls inside an existing validated login handler using SignInManager. The application must already configure its Identity store, lockout policy and user eligibility.

Weakness when the design relies on Identity lockout: failures are not counted.

var result = await signInManager.PasswordSignInAsync(
    userName, password, isPersistent: false, lockoutOnFailure: false);

Safer: count password failures toward the configured policy.

var result = await signInManager.PasswordSignInAsync(
    userName, password, isPersistent: false, lockoutOnFailure: true);

This flag is not a complete login handler. Preserve handling for RequiresTwoFactor, IsLockedOut, IsNotAllowed and Succeeded; do not grant access merely because the call returned. Review MaxFailedAccessAttempts, DefaultLockoutTimeSpan and the existing account's lockout-enabled state. AllowedForNewUsers concerns newly created accounts. See Microsoft's Identity configuration.

Balance protection and availability

Choose thresholds for the application's threat model. Add controlled recovery, monitor distributed failures and return suitably generic login errors. Permanent or easily triggered lockouts can let someone deny another user access. Rate limiting should account for shared networks and distributed clients; IP-only counters are insufficient. Follow OWASP's authentication guidance.

Regression check

With a disposable account, verify failures increment the intended counter, the threshold blocks another attempt, and the documented recovery works. Verify an unaffected account and the MFA branch still behave correctly. Never run guessing tests against real users. See password policy.