Brute-force Block Without Password Attempt Failure in Logs
Last Updated:
Overview
Cause
Solution
These failures still count towards the brute force protection threshold trigger, so can appear to be a user being blocked without any login activity beforehand. This could be caused by users leaving login pages open for too long and causing the state to become invalid or cookies to expire, or starting a new login transaction but submitting the credentials in a previously opened tab/window, or a brute force attack.
As it is intended to not log these kinds of failures to reduce potential noise in tenant logs, please raise a feature request to have our product team consider alternative approaches to this if you would like to have a record of this kind of failed login.