AD Security Groups - Account Lockouts

Justin Jackson 1 Reputation point
2020-08-04T16:40:29.317+00:00

We recently created an RDS server for our applications and the login page is public facing because we do not want the users to access via VPN. There is a concern that we may be vulnerable to a brute force attack that may cause higher level employees accounts to get locked out. If I create a security group in AD for the small group of users who access RDS and assign it to them, will a user who is not in this group still get locked out from unsuccessful login attempts on the RDS even though they do not have access to RDS in the first place?

Remote Desktop
Remote Desktop
A Microsoft app that connects remotely to computers and to virtual apps and desktops.
4,225 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,380 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Eleven Yu (Shanghai Wicresoft Co,.Ltd.) 10,671 Reputation points Microsoft Vendor
    2020-08-05T02:39:49.36+00:00

    Hi,

    The root cause of account lockouts is incorrect credentials. Incorrect credentials will cause unsuccessful login, then the user's account get locked.

    So, a user who is not in the group will be denied to access to RDS but the account will not be locked if there is no password error during login attempt.

    Thanks,
    Eleven

    0 comments No comments