MFA account lockout

S.R 0 Reputation points
2023-02-03T11:32:57.8333333+00:00

Hi,

I've tried to configure the MFA Account lockout and set it to 5 tries before the account gets locked out.

User's image

I've setup a test account and tried:

  • Login to O365 and introduce a bad MFA code more than 5 times.
  • Login to O365 and ask for a MFA code more than 5 times.

But the account is not locked out. Is there any other requirement I need to accomplish more than configure this?

When exactly is supposed to be triggered the lockout: 1) when introducing the wrong code or 2) when asking for many codes?

Thank you for your help!

Microsoft Security | Microsoft Entra | Microsoft Entra ID
{count} votes

1 answer

Sort by: Most helpful
  1. Rafael da Rocha 5,251 Reputation points
    2023-02-03T12:21:21.2166667+00:00

    Hello,

    it seems the lockout action applies only to users that enter a PIN to authenticate, in association with the now deprecated Azure MFA server.
    https://learn.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-mfasettings#account-lockout

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.