{"id":818,"date":"2023-08-04T15:30:55","date_gmt":"2023-08-04T07:30:55","guid":{"rendered":"https:\/\/www.ruianding.com\/blog\/?p=818"},"modified":"2023-08-31T01:49:05","modified_gmt":"2023-08-30T17:49:05","slug":"adfs-external-smart-lockout-terminology","status":"publish","type":"post","link":"https:\/\/www.ruianding.com\/blog\/adfs-external-smart-lockout-terminology\/","title":{"rendered":"ADFS External Smart Lockout Terminology"},"content":{"rendered":"\n<p><strong>FamiliarLocation:<\/strong> During an authentication request, ESL <strong>checks all presented IPs.<\/strong> These IPs will be a combination of <strong>network IP, forwarded IP, etc.<\/strong> If the request is successful, all of the IPs are added to the Account Activity table as \u201cfamiliar IPs\u201d. If the request has all the IPs present in the \u201cfamiliar IPs\u201d, the request will be treated as a \u201cFamiliar\u201d location &#8212; (20 records, FIFO)<\/p>\n\n\n\n<p><strong>UnknownLocation:<\/strong> If a request that comes in <strong>has at least one IP not present in the existing \u201cFamiliarLocation\u201d list,<\/strong> then the request will be treated as an \u201cUnknown\u201d location. This is to handle proxying scenarios such as Exchange Online legacy authentication where Exchange Online addresses handle both successful and failed requests.<\/p>\n\n\n\n<p><strong>badPwdCount:<\/strong> A value representing the number of times an incorrect password was submitted and the authentication was unsuccessful. For each user,<strong> separate counters are kept for Familiar Locations and Unknown Locations.<\/strong><\/p>\n\n\n\n<p><strong>UnknownLockout\/FamiliarLockout:<\/strong> A Boolean value per user if the user is locked out from accessing from unknown\/familar locations. This value is calculated based on the badPwdCount and ExtranetLockoutThreshold.<\/p>\n\n\n\n<p><strong>ExtranetLockoutThreshold:<\/strong> This value determines the maximum number of bad password attempts. When the threshold is reached, ADFS will reject requests from the extranet until the observation window has passed.<\/p>\n\n\n\n<p><strong>ExtranetObservationWindow:<\/strong> This value determines the duration that username and password requests are locked out. When the window has passed, ADFS will start to perform username and password authentication again.<\/p>\n\n\n\n<p><strong>ExtranetLockoutRequirePDC:<\/strong> When enabled, extranet lockout requires a primary domain controller (PDC). When disabled, extranet lockout will fall back to another domain controller in case the PDC is unavailable.<\/p>\n\n\n\n<p><strong>ExtranetLockoutMode<\/strong>: Controls log only vs enforced mode of Extranet Smart Lockout<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>ADPasswordCounter <\/strong>This is the <strong>legacy AD FS &#8220;extranet soft lockout&#8221; mode<\/strong>, which does not differentiate based on location. This is the <strong>default value<\/strong>.<\/li>\n\n\n\n<li><strong>ADFSSmartLockoutLogOnly: <\/strong>Extranet Smart Lockout is enabled, but AD FS will only write admin and audit events but will not reject authentication requests. This mode is intended to initially be enabled for FamiliarLocation to be populated before \u2018ADFSSmartLockoutEnforce&#8217; is enabled.<\/li>\n\n\n\n<li><strong>ADFSSmartLockoutEnforce: <\/strong>Full support for blocking authentication requests when thresholds are reached from unknown\/familiar locations.<\/li>\n<\/ul>\n\n\n\n<p class=\"has-pale-cyan-blue-background-color has-background has-small-font-size\">Both IPv4 and IPv6 addresses are supported.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>FamiliarLocation: During an authentication request, ESL checks all presented IPs. These IPs will be a combination of network IP, forwarded IP, etc. If the request is successful, all of the IPs are added to the Account Activity table as \u201cfamiliar IPs\u201d. If the request has all the IPs present in the \u201cfamiliar IPs\u201d, the request [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_themeisle_gutenberg_block_has_review":false,"footnotes":""},"categories":[42],"tags":[5],"class_list":["post-818","post","type-post","status-publish","format-standard","hentry","category-adfs","tag-adfs"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.0 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>ADFS External Smart Lockout Terminology - \u6781\u7b80IT\uff5cSimpleIT<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.ruianding.com\/blog\/adfs-external-smart-lockout-terminology\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"ADFS External Smart Lockout Terminology - \u6781\u7b80IT\uff5cSimpleIT\" \/>\n<meta property=\"og:description\" content=\"FamiliarLocation: During an authentication request, ESL checks all presented IPs. These IPs will be a combination of network IP, forwarded IP, etc. If the request is successful, all of the IPs are added to the Account Activity table as \u201cfamiliar IPs\u201d. If the request has all the IPs present in the \u201cfamiliar IPs\u201d, the request [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.ruianding.com\/blog\/adfs-external-smart-lockout-terminology\/\" \/>\n<meta property=\"og:site_name\" content=\"\u6781\u7b80IT\uff5cSimpleIT\" \/>\n<meta property=\"article:published_time\" content=\"2023-08-04T07:30:55+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2023-08-30T17:49:05+00:00\" \/>\n<meta name=\"author\" content=\"Ruian Ding\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Ruian Ding\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.ruianding.com\/blog\/adfs-external-smart-lockout-terminology\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.ruianding.com\/blog\/adfs-external-smart-lockout-terminology\/\"},\"author\":{\"name\":\"Ruian Ding\",\"@id\":\"https:\/\/www.ruianding.com\/blog\/#\/schema\/person\/440d88575b7dc819a4cefc8c4199db3b\"},\"headline\":\"ADFS External Smart Lockout Terminology\",\"datePublished\":\"2023-08-04T07:30:55+00:00\",\"dateModified\":\"2023-08-30T17:49:05+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.ruianding.com\/blog\/adfs-external-smart-lockout-terminology\/\"},\"wordCount\":362,\"publisher\":{\"@id\":\"https:\/\/www.ruianding.com\/blog\/#\/schema\/person\/440d88575b7dc819a4cefc8c4199db3b\"},\"keywords\":[\"ADFS\"],\"articleSection\":[\"ADFS\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.ruianding.com\/blog\/adfs-external-smart-lockout-terminology\/\",\"url\":\"https:\/\/www.ruianding.com\/blog\/adfs-external-smart-lockout-terminology\/\",\"name\":\"ADFS External Smart Lockout Terminology - \u6781\u7b80IT\uff5cSimpleIT\",\"isPartOf\":{\"@id\":\"https:\/\/www.ruianding.com\/blog\/#website\"},\"datePublished\":\"2023-08-04T07:30:55+00:00\",\"dateModified\":\"2023-08-30T17:49:05+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/www.ruianding.com\/blog\/adfs-external-smart-lockout-terminology\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.ruianding.com\/blog\/adfs-external-smart-lockout-terminology\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.ruianding.com\/blog\/adfs-external-smart-lockout-terminology\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.ruianding.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"ADFS External Smart Lockout Terminology\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.ruianding.com\/blog\/#website\",\"url\":\"https:\/\/www.ruianding.com\/blog\/\",\"name\":\"Ruian's Tech Troubleshooting Toolbox\",\"description\":\"Debug the World.\",\"publisher\":{\"@id\":\"https:\/\/www.ruianding.com\/blog\/#\/schema\/person\/440d88575b7dc819a4cefc8c4199db3b\"},\"alternateName\":\"\u4e01\u777f\u5b89\u7684\u6280\u672f\u5206\u4eab\u535a\u5ba2\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.ruianding.com\/blog\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\/\/www.ruianding.com\/blog\/#\/schema\/person\/440d88575b7dc819a4cefc8c4199db3b\",\"name\":\"Ruian Ding\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.ruianding.com\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2023\/05\/logo.png\",\"contentUrl\":\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2023\/05\/logo.png\",\"width\":284,\"height\":284,\"caption\":\"Ruian Ding\"},\"logo\":{\"@id\":\"https:\/\/www.ruianding.com\/blog\/#\/schema\/person\/image\/\"},\"description\":\"I am currently a Support Specialist at NIO, focusing on cloud-related issues for NIO Power. Previously, at Microsoft Entra ID, I specialized in identity and access management (IAM), including device registration, Windows Hello for Business (WHfB), multi-factor authentication (MFA), and single sign-on (SSO). In addition to my core expertise, I have a strong foundation in Active Directory, Servers, Cloud Computing, Network Administration, and Front-end Web Development. This diverse technical skill set enables me to effectively handle a wide range of challenges in a fast-paced IT environment.\",\"sameAs\":[\"https:\/\/www.ruianding.com\"],\"url\":\"https:\/\/www.ruianding.com\/blog\/author\/ruiand\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"ADFS External Smart Lockout Terminology - \u6781\u7b80IT\uff5cSimpleIT","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.ruianding.com\/blog\/adfs-external-smart-lockout-terminology\/","og_locale":"en_US","og_type":"article","og_title":"ADFS External Smart Lockout Terminology - \u6781\u7b80IT\uff5cSimpleIT","og_description":"FamiliarLocation: During an authentication request, ESL checks all presented IPs. These IPs will be a combination of network IP, forwarded IP, etc. If the request is successful, all of the IPs are added to the Account Activity table as \u201cfamiliar IPs\u201d. If the request has all the IPs present in the \u201cfamiliar IPs\u201d, the request [&hellip;]","og_url":"https:\/\/www.ruianding.com\/blog\/adfs-external-smart-lockout-terminology\/","og_site_name":"\u6781\u7b80IT\uff5cSimpleIT","article_published_time":"2023-08-04T07:30:55+00:00","article_modified_time":"2023-08-30T17:49:05+00:00","author":"Ruian Ding","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Ruian Ding","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.ruianding.com\/blog\/adfs-external-smart-lockout-terminology\/#article","isPartOf":{"@id":"https:\/\/www.ruianding.com\/blog\/adfs-external-smart-lockout-terminology\/"},"author":{"name":"Ruian Ding","@id":"https:\/\/www.ruianding.com\/blog\/#\/schema\/person\/440d88575b7dc819a4cefc8c4199db3b"},"headline":"ADFS External Smart Lockout Terminology","datePublished":"2023-08-04T07:30:55+00:00","dateModified":"2023-08-30T17:49:05+00:00","mainEntityOfPage":{"@id":"https:\/\/www.ruianding.com\/blog\/adfs-external-smart-lockout-terminology\/"},"wordCount":362,"publisher":{"@id":"https:\/\/www.ruianding.com\/blog\/#\/schema\/person\/440d88575b7dc819a4cefc8c4199db3b"},"keywords":["ADFS"],"articleSection":["ADFS"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.ruianding.com\/blog\/adfs-external-smart-lockout-terminology\/","url":"https:\/\/www.ruianding.com\/blog\/adfs-external-smart-lockout-terminology\/","name":"ADFS External Smart Lockout Terminology - \u6781\u7b80IT\uff5cSimpleIT","isPartOf":{"@id":"https:\/\/www.ruianding.com\/blog\/#website"},"datePublished":"2023-08-04T07:30:55+00:00","dateModified":"2023-08-30T17:49:05+00:00","breadcrumb":{"@id":"https:\/\/www.ruianding.com\/blog\/adfs-external-smart-lockout-terminology\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.ruianding.com\/blog\/adfs-external-smart-lockout-terminology\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.ruianding.com\/blog\/adfs-external-smart-lockout-terminology\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.ruianding.com\/blog\/"},{"@type":"ListItem","position":2,"name":"ADFS External Smart Lockout Terminology"}]},{"@type":"WebSite","@id":"https:\/\/www.ruianding.com\/blog\/#website","url":"https:\/\/www.ruianding.com\/blog\/","name":"Ruian's Tech Troubleshooting Toolbox","description":"Debug the World.","publisher":{"@id":"https:\/\/www.ruianding.com\/blog\/#\/schema\/person\/440d88575b7dc819a4cefc8c4199db3b"},"alternateName":"\u4e01\u777f\u5b89\u7684\u6280\u672f\u5206\u4eab\u535a\u5ba2","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.ruianding.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":["Person","Organization"],"@id":"https:\/\/www.ruianding.com\/blog\/#\/schema\/person\/440d88575b7dc819a4cefc8c4199db3b","name":"Ruian Ding","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.ruianding.com\/blog\/#\/schema\/person\/image\/","url":"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2023\/05\/logo.png","contentUrl":"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2023\/05\/logo.png","width":284,"height":284,"caption":"Ruian Ding"},"logo":{"@id":"https:\/\/www.ruianding.com\/blog\/#\/schema\/person\/image\/"},"description":"I am currently a Support Specialist at NIO, focusing on cloud-related issues for NIO Power. Previously, at Microsoft Entra ID, I specialized in identity and access management (IAM), including device registration, Windows Hello for Business (WHfB), multi-factor authentication (MFA), and single sign-on (SSO). In addition to my core expertise, I have a strong foundation in Active Directory, Servers, Cloud Computing, Network Administration, and Front-end Web Development. This diverse technical skill set enables me to effectively handle a wide range of challenges in a fast-paced IT environment.","sameAs":["https:\/\/www.ruianding.com"],"url":"https:\/\/www.ruianding.com\/blog\/author\/ruiand\/"}]}},"_links":{"self":[{"href":"https:\/\/www.ruianding.com\/blog\/wp-json\/wp\/v2\/posts\/818","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.ruianding.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.ruianding.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.ruianding.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.ruianding.com\/blog\/wp-json\/wp\/v2\/comments?post=818"}],"version-history":[{"count":2,"href":"https:\/\/www.ruianding.com\/blog\/wp-json\/wp\/v2\/posts\/818\/revisions"}],"predecessor-version":[{"id":822,"href":"https:\/\/www.ruianding.com\/blog\/wp-json\/wp\/v2\/posts\/818\/revisions\/822"}],"wp:attachment":[{"href":"https:\/\/www.ruianding.com\/blog\/wp-json\/wp\/v2\/media?parent=818"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.ruianding.com\/blog\/wp-json\/wp\/v2\/categories?post=818"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.ruianding.com\/blog\/wp-json\/wp\/v2\/tags?post=818"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}