About Account Lockout
To limit password guessing, ToolHound locks a user account after repeated failed sign-in attempts.
An account is locked after [5] failed attempts within [5] minutes. While the account is locked, ToolHound refuses the sign-in even if the password is correct, and the login page states that the account is locked and when it can be used again.
The following count as failed attempts:
- An incorrect password on the browser login page.
- An incorrect two factor authentication code.
- [Confirm whether TH6 Mobile and Kiosk sign-ins count toward the same lockout.]
The lockout clears on its own after [lockout duration]. No administrator action is needed to release it.
Note callout: Before version 6.2026.902.1 the lockout policy did not apply to the browser login page. A user who is used to retrying a forgotten password many times will encounter this for the first time after the update.
If you are locked out
Wait for the lockout period to end and try again. If you do not remember your password, use Forgot / Reset Password rather than guessing — a reset does not count toward the lockout. See Using Forgot / Reset Password.
If you administer ToolHound
[Confirm and document: can an administrator clear a lockout early, and where — Utilities › Users › Editing a User?]
The lockout thresholds are set in the application configuration and are not editable from the Settings page. [On Premise: confirm the setting name and file. Cloud: state that the values are fixed.]