Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteTo reduce password-spraying risk in Microsoft Entra ID, combine smart lockout with broad multifactor authentication (MFA), block legacy authentication, and prepare safe recovery routes. Smart lockout is enabled by default, but it is only one layer; it does not replace an MFA policy or guarantee that legitimate users will never be locked out.
The steps and settings below are specific to Microsoft Entra ID. Other identity platforms use different controls and defaults.
What smart lockout does—and what it does not do
Password spraying tests a small number of commonly used passwords against many accounts. Smart lockout detects repeated failed sign-ins and temporarily prevents further attempts against an account, making it harder to keep guessing against that user. It is always on in Microsoft Entra ID.
It is not a universal threshold you can set once and forget. Microsoft says lockout behavior can vary slightly across data centers, and familiar and unfamiliar locations have separate counters. A genuine user can still be locked out, so pair the control with MFA and a recovery plan.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Default thresholds and timing
Microsoft documents these defaults:
| Tenant environment | Default failed-attempt threshold | Initial lockout |
|---|---|---|
| Azure Public | 10 attempts | 60 seconds |
| Microsoft Azure operated by 21Vianet | 10 attempts | 60 seconds |
| Azure US Government | 3 attempts | 60 seconds |
Subsequent lockouts lengthen, but Microsoft does not disclose the increase rate. Custom organization-specific settings require Microsoft Entra ID P1 or higher; custom settings are not supported in 21Vianet tenants. Confirm the tenant’s actual region and license before planning a custom threshold.
Where to review settings
In the Microsoft Entra admin center, go to Entra ID > Authentication methods > Password protection. Microsoft’s documented instructions require the Authentication Policy Administrator role or higher. Review the tenant’s current configuration and licensing before changing it; do not copy a threshold from another organization without considering user error, attack patterns, and hybrid lockout behavior. Microsoft’s smart lockout documentation describes the settings and defaults.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
How to require MFA for users
For a custom policy, Microsoft recommends a baseline Conditional Access policy that targets all users and all resources and requires MFA, without app exclusions. Plan exceptions deliberately: emergency-access accounts need a way to recover from policy misconfiguration, while service accounts and service principals need appropriate treatment. User-scoped Conditional Access does not cover service principals; use workload identity controls where applicable.
Choose security defaults or Conditional Access
| Approach | Best fit | What to account for |
|---|---|---|
| Security defaults | Organizations seeking a preconfigured baseline | Microsoft says defaults require users to register for MFA and block legacy authentication. They offer less policy-level customization than Conditional Access. |
| Conditional Access | Organizations that need to define and manage their own policy scope and requirements | Configure a baseline policy for all users and resources, and plan emergency-access exclusions and service identities carefully. |
Microsoft’s security-defaults guidance says that MFA combined with blocking legacy authentication stops more than 99.9% of common identity-related attacks. That is Microsoft’s claim about the combined controls, not a tenant-specific guarantee or a password-spraying-only statistic. When enabling security defaults, Microsoft’s guidance directs administrators to revoke existing tokens so users must register; check the current deployment flow before applying that step. Read Microsoft’s security defaults overview.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
For organizations using Conditional Access, create a policy in the Entra admin center and configure its users, target resources, grant control, and exclusions deliberately. Microsoft recommends an all-users, all-resources MFA baseline. Use the current Conditional Access documentation for the exact admin-center workflow, which can change. Microsoft’s all-users MFA policy guidance covers the baseline policy.
Choose an MFA strength that fits your environment
Entra authentication strengths let administrators require a defined level of authentication. Microsoft’s documented categories include MFA, passwordless MFA, and phishing-resistant MFA. Stronger requirements can improve resistance to credential theft, but only if users’ devices, applications, enrollment, and recovery processes support them.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
| Strength | Trade-off to assess |
|---|---|
| MFA | Broad starting point; confirm that the allowed methods meet the organization’s threat model. |
| Passwordless MFA | Removes password entry from supported sign-in flows, but requires compatible methods and enrollment. |
| Phishing-resistant MFA | Designed for stronger resistance to phishing; verify application, device, and user compatibility before making it mandatory. |
FIDO2 security keys are one physical option, not a universal recommendation: compatibility depends on the identity setup, endpoint, and sign-in flow. Select organization-approved methods and confirm support before deployment. Microsoft’s authentication strengths documentation explains the categories, and its passwordless authentication overview describes supported approaches.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Coordinate Entra and Active Directory lockout in pass-through authentication
If the tenant uses pass-through authentication with on-premises Active Directory Domain Services (AD DS), coordinate the thresholds and durations. Microsoft advises setting the Entra threshold below the AD DS threshold, setting the AD DS threshold at least two or three times higher, and making the Entra lockout duration longer than the AD DS duration. This ordering is intended to reduce the risk that attempts reach AD DS and lock out users there.
Recommended Free Tools
Best Value
- POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
| Setting | Microsoft’s example |
|---|---|
| Entra failed-attempt threshold | 10 attempts |
| AD DS failed-attempt threshold | 20 attempts |
| Entra lockout duration | 120 seconds |
| AD DS lockout duration | 60 seconds |
These are Microsoft’s example values, not a universal prescription. Validate the relationship against the organization’s actual pass-through configuration, AD DS policies, user behavior, and operational recovery needs. Microsoft’s smart lockout guidance documents this hybrid relationship.
Plan recovery and protect administrative access
Keep emergency-access accounts outside the baseline Conditional Access policy so administrators can recover from a policy mistake or lockout. Protect those accounts according to the organization’s security procedures and monitor their use. Do not treat ordinary service identities as emergency users: service principals are not governed by user-scoped Conditional Access, so evaluate workload identity protections separately.
For users, enable and test self-service password reset (SSPR) where appropriate. Microsoft distinguishes the recovery flow based on whether someone knows their current password: “I forgot my password” is the reset path for a forgotten password, while “I know my password” is for changing a known password. Pilot SSPR with a selected group, enable notifications, and set method requirements deliberately. Microsoft recommends requiring registration of at least one more method than the number required to complete a reset, so users have a recovery option if one method is unavailable. Microsoft’s SSPR deployment guidance covers rollout and configuration.
Quick Recap
Deployment checklist
- Confirm the tenant environment, license, authentication methods, and whether sign-ins use pass-through authentication.
- Review the default smart lockout threshold and duration at Entra ID > Authentication methods > Password protection; change organization-specific values only when the tenant supports them and the policy has been assessed.
- Choose security defaults for a preconfigured baseline or configure a Conditional Access policy that requires MFA for all users and resources, with carefully planned emergency-access exclusions.
- Select an authentication strength and methods that users, applications, and endpoints can support; validate enrollment and recovery before broad enforcement.
- If using pass-through authentication, verify the Entra and AD DS thresholds and durations together rather than tuning either policy in isolation.
- Pilot SSPR and the MFA policy, test sign-in and recovery paths, then expand deployment while monitoring lockouts and administrative access.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →

