ID-05: Configure Smart Lockout Protection
Frequently asked questions about implementing and managing the ID-05 security control in Microsoft 365 and Entra ID.
QWhat is ID-05 (Configure Smart Lockout Protection)?▼
ID-05 is a security control that password spray attacks try common passwords across many accounts. smart lockout detects these patterns and blocks attackers while allowing legitimate users to authenticate. weak settings leave you vulnerable. It requires that smart lockout is enabled with appropriate thresholds and lockout threshold is 5 or fewer failed attempts, custom banned password list is configured.
QWhy is Configure Smart Lockout Protection important for Microsoft 365 security?▼
Password spray attacks try common passwords across many accounts. Smart lockout detects these patterns and blocks attackers while allowing legitimate users to authenticate. Weak settings leave you vulnerable.
QHow do I implement ID-05 in my tenant?▼
ID-05 requires manual implementation. Requires Entra ID admin access to configure authentication methods
QWhat license do I need for ID-05?▼
This control can be implemented with any Microsoft 365 subscription, including free Azure AD.
QWhich security baseline includes ID-05?▼
ID-05 is included in the TrueConfig Recommended Secure baseline (Level 1). This is the foundation level suitable for most organizations.
5
Questions
1
Related Controls
—
Categorized
Related Resources
Still have questions?
Our security experts are here to help. Start a free trial and get personalized guidance for your Microsoft 365 environment.
Start Free Trial