Endpoint Protection

 View Only
  • 1.  SEPM 12.1 account lockout duration

    Posted Jun 04, 2015 01:53 AM

    Hi, just want to check and confirm something regarding SEPM 12.1 authentication.

    For the account lockout duration, is it possible to set it so that the account is permanently locked until another administrator unlocks it?

    In the configuration field for this setting, I can only set it to lock between 1 to 60 minutes, so just want an official explanation from Symantec if the above is possible, and if so, where to set it.

     

    Thanks.



  • 2.  RE: SEPM 12.1 account lockout duration
    Best Answer

    Posted Jun 04, 2015 01:55 AM

    see this

     

    Symantec Endpoint Protection Manager locks out an administrator for a certain length of time after a number of unsuccessful logon attempts. By default, the management server locks out an administrator for 15 minutes after five failed attempts.

    You cannot unlock the administrator account without waiting for the specified period of time to pass. However, you can disable the administrator account from locking, though this action does not unlock the account. You can also change the number of unsuccessful logon attempts and wait the time that is permitted before the account is locked. A password change does not reset or otherwise affect the lockout interval.

    For added security in 12.1.5 and later, after the first lockout the lockout interval doubles with each additional lockout. Symantec Endpoint Protection Manager reinstates the original lockout interval after a successful logon occurs or after 24 hours pass since the first lockout. For example, if the original lockout interval is 15 minutes, the second lockout triggers a 30-minute lockout interval. The third lockout triggers a 60-minute lockout interval. If the first lockout occurs at 2:00 P.M. on Thursday, then the 24-hour period ends 2:00 P.M. Friday, and Symantec Endpoint Protection Manager resets the lockout interval to 15 minutes.

    To configure an administrator's account to lock after too many logon attempts

    1. In the console, click Admin > Administrators.

    2. Under Administrators, select the administrator account that is locked.

    3. Under Tasks, click Edit the administrator.

    4. On the General tab, uncheck Lock the account after the specified number of unsuccessful logon attempts.

    See Resetting a forgotten Symantec Endpoint Protection Manager password.

    See Changing the password for an administrator account.

    See Enabling Symantec Endpoint Protection Manager logon passwords to never expire.

     

    https://support.symantec.com/en_US/article.HOWTO80757.html



  • 3.  RE: SEPM 12.1 account lockout duration
    Best Answer

    Posted Jun 04, 2015 02:16 AM

    Not possible max is 60 mins, 



  • 4.  RE: SEPM 12.1 account lockout duration
    Best Answer

    Trusted Advisor
    Posted Jun 04, 2015 05:57 AM

    Hello,

    For the account lockout duration, is it possible to set it so that the account is permanently locked until another administrator unlocks it?

    Not possible that the account is permanently locked. There is a 60 min lockout interval.

    However, you being a System Administrator on SEPM, can unlock it during this 60 min interval.

     



  • 5.  RE: SEPM 12.1 account lockout duration
    Best Answer

    Posted Jun 04, 2015 06:27 AM

    Nope. It unlock after a specific time but cannot be set to permanent.



  • 6.  RE: SEPM 12.1 account lockout duration
    Best Answer

    Broadcom Employee
    Posted Jun 04, 2015 07:36 AM

    Hi,

    Thank you for posting in Symantec community.

    Q. For the account lockout duration, is it possible to set it so that the account is permanently locked until another administrator unlocks it?

    --> It's not possible to permanently locked an accunt until another administrator unlocks it.



  • 7.  RE: SEPM 12.1 account lockout duration

    Posted Jun 04, 2015 08:16 PM

    Thanks for the reply all, that answers my question