About Login Tracking

Login Tracking enhances security. If you enable login tracking, you can:

You enable login tracking and specify the maximum number of unsuccessful logins allowed by using the Security Controls window as described in Enable or Disable Login Tracking. You can access this window from both the Users and Security Groups (SP) applications.

When login tracking is enabled, the system keeps track of all login attempts-successful and unsuccessful. After each successful login, the user again has the maximum allowed number of chances to log in. If the failures for a user reach the maximum number allowed, the system automatically changes the user's status to BLOCKED. The user is prevented from logging in until an administrator unblocks him using the Change Status window in the Users application.

Login tracking is required if you use electronic signature. Refer to the System Administrator's Guide for information on how to use that option.

Example

The number of Login Attempts Allowed is set to 3. A user forgets his password and attempts to log in three times using an incorrect password. After each of the first two attempts he receives an "Invalid username/password" message and tries to log in again. After the third failed attempt, the system changes his status to BLOCKED and the user receives the following message:

"Your User ID has been blocked from the system. Please contact your System Administrator."

The user can no longer log in to the system, even if he uses the correct password. He contacts his System Administrator and describes the problem. The System Administrator uses the Manage Session action in the Security Groups (SP) application to check the User ID, User Status, and Last Login Attempt for the blocked user.

The System Administrator opens the Users application, selects the user, selects the Change Status action and changes the user's status from BLOCKED to ACTIVE.

The user once again has three chances to log in.

 

Note: If implementation uses an application server to authenticate with a directory, you will not use the system to perform some functions. Instead, these functions will be performed in the directory and synchronized into the system. These functions include: