Account Locking
Definition
The process of temporarily disabling user accounts on a system or domain.
How it works
Management servers with enterprise policies for account management provide the ability to enable and disable account for given rules. The rules may include specific periods of time (eg. weekend, plant shutdown, leave periods), specific user types or groups, or individual users.
Considerations
- Local accounts caches vs centralized account management
- Single Sign-on
- Role based vs Attribute based systems
Examples of account configuration stores
- Directory Services
- Active Directory
- RADIUS
- LDAP
- Oracle User Account Management
- JumpCloud
Artifact Relationships:
This defensive technique is related to specific artifacts. Click the artifact node for more information.
Related ATT&CK Techniques:
These offensive techniques are determined related because of the way this defensive technique,, .
References
The following references were used to develop the Account Locking knowledge-base article.
(Note: the consideration of references does not imply specific functionality exists in an offering.)