SC‑300 Study Portal Path 3

Unit 7: Configure Smart Lockout Thresholds

What is Smart Lockout

Smart lockout helps protect accounts from brute-force and password guessing attacks while reducing impact to legitimate users.

Default behavior:

Smart lockout also:

Federated deployments:

Smart lockout is:

Behavior and Considerations

🧪 Example

But this only happens if the user’s traffic is routed differently—not from a single bad password attempt.

Pass-Through Authentication Considerations

Configuration guidelines:

Example:

This ensures that smart lockout in Entra stops attacks before they lock out accounts in on-prem AD.

🔐 Why Entra Lockout Should Trigger First

✅ 1. Stops Attacks Before They Reach AD

⏱️ Why Entra Lockout Should Last Longer

Example Scenario:

Setting Entra AD DS
Lockout Threshold 5 attempts 10 attempts
Lockout Duration 120 seconds 60 seconds

✅ This gives legitimate users a chance to recover without being locked out on-prem.

Would you like a lab checklist to validate Smart Lockout behavior with PTA and simulate thresholds across Entra and AD?