Account Lockout on multiple invalid login attempts
Feb 26, 2019
24021
As part of our initiative to make HappyFox more secure, we have introduced new features that aim at preventing unauthorized access to the application.
The following features are now available for all HappyFox users (contact & agent)
Account Lockout
HappyFox enforces a temporary 60 minute lockout period if an agent or contact enters invalid credentials consecutively for 5 times. The login screen displays the attempts remaining for a user before a lockout is triggered.
Unsuccessful agent login
Unsuccessful contact login
In the event of a lockout, the agent/contact is automatically notified via email. The email contains the following information for last successful login and for the past 5 unsuccessful login attempts
-
Timestamp
-
IP information
-
Location
-
Browser details
-
Operating System details
Once an account is locked out, the agent/contact can do either of the following
-
Wait for 60 minutes so that the account lock is automatically released
-
Send an automated email request to the administrator/s requesting manual unlock
When an agent/contact is locked out of HappyFox, their active HappyFox sessions remain unaffected. New sessions i.e., new login attempts will be restricted (including SSO logins).