Locked users
The accounts locked after too many failed sign-in attempts: how you see them, what the statuses mean and how you unlock them.
The Locked Users section (Locked Users Management, "View and manage accounts locked due to too many failed login attempts") is the only place from which an account gets unlocked.
The locking rules
Only wrong passwords typed with an email address that exists are counted:
| Failed attempts | Effect |
|---|---|
| 1 to 9 | no lock |
| 10 to 19 | 15 minute lock |
| 20 to 29 | 1 hour lock; the administrators receive Alert Sicurezza: Account Bloccato - {email} (this subject is sent in Italian) |
| 30 or more | permanent ban; the administrators receive CRITICO: Account Bannato Permanentemente - {email} (also sent in Italian) |
A successful sign-in resets the counter. A password reset clears the temporary lock but not the permanent ban. There is also a limit per network connection (5 attempts in 15 minutes, then a 30 minute pause) that does not show up in this section and expires on its own.
The list
You see the people with a permanent ban, with a temporary lock still running, or with at least 5 failed attempts. Columns: Email, Name, Status (Permanently Banned, Temporarily Locked, Multiple Attempts, with Ban reason: {reason} where there is one), Failed Attempts, Last Failed Login, Actions. The Refresh button reloads the list; when there is nobody: No users currently locked.
Unlocking
Press Unlock Account and confirm in the Confirm Account Unlock window ("Are you sure you want to unlock the account for {email}? All failed attempts will be reset."). The unlock resets the attempts, the lock expiry and the permanent ban, and it is written to the audit log. Confirmation: Account unlocked successfully.