Microsoft announced today that IT admins can now configure any Windows system still receiving security updates to automatically block brute force attacks targeting local administrator accounts via a group policy…
As a result, Windows 11 systems where the policy is toggled on automatically lock user accounts (including Administrator accounts) for 10 minutes after 10 failed sign-in attempts within 10 minutes…
Today, almost three months after Weston’s announcement, Microsoft revealed that the same account lockout policy is now available on any Windows system where the October 2022 cumulative updates are installed.
“In an effort to prevent further brute force attacks/attempts, we are implementing account lockouts for Administrator accounts,”..
This group policy will be enabled by default on all new machines running Windows 11 22H2 or those where the October 2022 Windows cumulative updates were installed before the initial setup when the Security Account Manager (SAM) database that stores the users’ passwords is first instantiated on the new machine…
![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
All Windows versions can now block admin brute-force attacks
Home » Forums » AskWoody support » Windows » Windows – other » All Windows versions can now block admin brute-force attacks
- This topic has 18 replies, 9 voices, and was last updated 7 months, 4 weeks ago.
AuthorTopicAlex5723
AskWoody PlusViewing 4 reply threadsAuthorReplies-
7ProSP1
AskWoody LoungerMicrosoft announced today that IT admins can now configure any Windows system still receiving security updates to automatically block brute attacks targeting local administrator accounts via a group policy…
Above emphasis mine.
Whar about Windows 7 and 8.1? They’re both still receiving security updates.
Are they privy to this new group policy or is Microsoft excluding both of them in the hopes this type of attack will obliterate them once and for all from their OS lineup so they finally won’t have to deal with them anymore?
-
b
ManagerAny appears to mean any:
Windows Server 2008 Datacenter ESU Windows Server 2008 Standard ESU Windows Server 2008 Enterprise ESU Windows 7 Enterprise ESU Windows 7 Professional ESU Windows 7 Ultimate ESU Windows Server 2008 R2 Enterprise ESU Windows Server 2008 R2 Standard ESU Windows Server 2008 R2 Datacenter ESU Windows Embedded Standard 7 ESU Windows Embedded POSReady 7 ESU Windows Server 2012 Windows Embedded 8 Standard Windows 8.1 Windows RT 8.1 Windows Server 2012 R2 Windows Embedded 8.1 Industry Enterprise Windows Embedded 8.1 Industry Pro Windows 10 Windows 10, version 1607, all editions Windows Server 2016, all editions Windows 10 Enterprise 2019 LTSC Windows 10 IoT Enterprise 2019 LTSC Windows 10 IoT Core 2019 LTSC Windows Server 2019 Windows 10 Enterprise Multi-Session, version 20H2 Windows 10 Enterprise and Education, version 20H2 Windows 10 IoT Enterprise, version 20H2 Windows 10 on Surface Hub Windows 10, version 21H1, all editions Windows 10, version 21H2, all editions Windows 11 version 21H2, all editions Windows 11 version 22H2, all editions Windows Server 2022 Less
…
KB5020282—Account lockout available for local administratorsWindows 11 Pro version 22H2 build 22621.1778 + Microsoft 365 + Edge
-
b
ManagerAdditionally, we are now enforcing password complexity on new machines if a local administrator account is used. The password must have at least three of the four basic character types (lower case, upper case, numbers, and symbols).
Windows 11 Pro version 22H2 build 22621.1778 + Microsoft 365 + Edge
alejr
AskWoody MVPThis group policy will be enabled by default on all new machines running Windows 11 22H2 or those where the October 2022 Windows cumulative updates were installed before the initial setup when the Security Account Manager (SAM) database that stores the users’ passwords is first instantiated on the new machine…
I’ve highlighted one extremely important catch I noticed in this announcement!
So, exactly how does one go about creating a “new” Security Account Manager database for existing PC’s after they receive the Oct update that enables this Group Policy?
-
b
ManagerSo, exactly how does one go about creating a “new” Security Account Manager database for existing PC’s after they receive the Oct update that enables this Group Policy?
You don’t. You just enable the group policy if it’s required.
Only the new default is not there unless it’s a new installation.
Windows 11 Pro version 22H2 build 22621.1778 + Microsoft 365 + Edge
-
Susan Bradley
Manager -
b
ManagerYou are probably going to have to remove/rebuild the older SAM database similar to other items where you may be protecting it going forward, but left over caches are still there.
Why would anyone need or want or to do that?
Destroy all accounts and passwords in order to obtain a lockout policy for local admins by default, instead of just setting that lockout policy?
So, if a new machine was set up and then had the October updates installed later, it will not be secure by default and will require the policy settings above.
Windows 11 Pro version 22H2 build 22621.1778 + Microsoft 365 + Edge
-
alejr
AskWoody MVP@b, thanks for clarifying that part of the announcement was about having it default to being enabled vs actually being able to enable it after the update gets installed!
The original link/quote from beeping computer didn’t really make that apparent.
1 user thanked author for this post.
-
Susan Bradley
Manager -
b
Manager -
Susan Bradley
Manager
-
-
-
Alex5723
AskWoody Plus-
b
ManagerIt’s a little weird that you have to set the Account lockout threshold first. I just set that to the recommended 10 and then the other three were automatically set to the recommended 10/Enabled/10 and became available for adjustment.
Windows 11 Pro version 22H2 build 22621.1778 + Microsoft 365 + Edge
-
lmacri
AskWoody PlusWindows 10 Pro October updates. Lockout Policy ‘Not Applicable’.
Hi Alex5723:
After installing my Oct 2022 Patch Tuesday updates I confirmed the account lockout policies on my Win 10 Pro v21H2 laptop are “Not Available” and look similar to the image you attached in post # 2487853.
———-
Dell Inspiron 5584 * 64-bit Win 10 Pro v21H2 build 19044.2130 * Firefox v105.0.3 * Microsoft Defender v4.18.2209.7-1.1.19700.3 * Malwarebytes Premium 4.5.15.215-1.0.1784 * Macrium Reflect Free v8.0.69791 user thanked author for this post.
-
b
Manageraccount lockout policies on my Win 10 Pro v21H2 laptop are “Not Available”
you have to set the Account lockout threshold first.
Windows 11 Pro version 22H2 build 22621.1778 + Microsoft 365 + Edge
1 user thanked author for this post.
-
Simon_Weel
AskWoody Plus-
geekdom
AskWoody_MVPIsn’t it ‘best practice’ to disable local admins?
Not necessarily. Some choose not to have a Microsoft account as administrator.
Edited to add: You were talking IT; I was talking individual. My answer has no bearing in this topic.
Carpe Diem {with backup and coffee}
offline▸ Win10Pro 2004.19041.572 x64 i3-3220 RAM8GB HDD Firefox83.0b3 WindowsDefender
offline▸ Acer TravelMate P215-52 RAM8GB Win11Pro 22H2.22621.1265 x64 i5-10210U SSD Firefox106.0 MicrosoftDefender
online▸ Win11Pro 22H2.22621.1778 x64 i5-9400 RAM16GB HDD Firefox115.0b3 MicrosoftDefender -
bbearren
AskWoody MVPIsn’t it ‘best practice’ to disable local admins?
“Local Computer Policy > Windows Settings > Security Settings > Account Policies > Account Lockout Policy > Allow Administrator account lockout” only applies to the built-in Administrator account, not the Administrators group.
I disable that account in Computer Management (Local) > Local Users and Groups > Users.
Always create a fresh drive image before making system changes/Windows updates; you may need to start over!We were all once "Average Users". We all have our own reasons for doing the things that we do to our systems, we don't need anyone's approval, and we don't all have to do the same things.1 user thanked author for this post.
Viewing 4 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Navigating Brian’s Club Login for the Best Deals (Awaiting moderation)
by
saharadumps
1 hour, 3 minutes ago -
Lost Title on mp3 files transferring files to my android phone
by
Alex
1 hour, 51 minutes ago -
Which Processor is Better?
by
RetiredGeek
1 hour, 52 minutes ago -
How to your travel and check your email when your old person?
by
Traveler
4 hours, 3 minutes ago -
May 2023 updates turn on disk performance counters?
by
marko
46 minutes ago -
iPad tips and tricks
by
Microfix
7 hours, 52 minutes ago -
Wine Updates
by
Alex5723
17 hours, 40 minutes ago -
WWDC 2023: Here’s everything Apple announced this week
by
Alex5723
21 hours, 16 minutes ago -
Malwarebytes Browser Guard extension in Firefox: where is the MB logo?
by
WCHS
2 hours, 6 minutes ago -
Android – or Android music app – file system
by
Richard Merchant
1 day ago -
Restore Points Being Deleted
by
George1
4 hours, 14 minutes ago -
Why millions of usable hard drives are being destroyed
by
Kathy Stevens
9 hours, 6 minutes ago -
YouTube Display is Very Large
by
kstephens43
1 day, 8 hours ago -
1Password and passkeys
by
Alex5723
1 day, 16 hours ago -
Macrium user error:selected volume guid?
by
Deo
1 day, 11 hours ago -
Windows 11 Insider Preview Build 22621.1835 and 22624.1835 released to BETA
by
joep517
2 days, 7 hours ago -
Unexpected HP Install Request anfter removal of Norton AV
by
MikeAL8
2 days, 3 hours ago -
Will Incontrol stop Windows 11 22H2 update, if used after update is paused?
by
sdanr
1 day, 7 hours ago -
Restoring a Bitlockered System Image with Macrium Reflect Free
by
sdanr
7 hours, 42 minutes ago -
Prevent emails from ever being seen in Outlook 2013
by
West Swan
2 days, 8 hours ago -
Windows Update
by
Richard Mitnick
1 day, 8 hours ago -
Vivaldi 6.1 with Bing chat , browsers mimic
by
Alex5723
1 day, 7 hours ago -
MS-DEFCON 2: Are you still on Windows 10 21H2?
by
Susan Bradley
4 hours, 1 minute ago -
Word 2021 – Print View problems
by
WSjrasnic
2 days, 13 hours ago -
Windows 11 Insider Preview build 25387 released to Canary
by
joep517
1 day, 4 hours ago -
Windows 11 Insider Preview build 23475 released to DEV
by
joep517
3 days, 7 hours ago -
WordPress added AI – Jetpack
by
Alex5723
3 days, 5 hours ago -
PXE Boot and Hyper-V virtual machines and other strange things
by
Simon_Weel
3 hours, 45 minutes ago -
Testing for adding table to post
by
alejr
3 days, 7 hours ago -
I honestly can’t tell if this is a scam or not
by
Susan Bradley
10 hours, 6 minutes ago
Recent blog posts
- MS-DEFCON 2: Are you still on Windows 10 21H2?
- June 2023 Office non-Security updates have been released
- Can we control the changes to our operating systems?
- Watch out for fake ‘Windows Defender’ scare
- Diagnostics and testing? Get it all done in a flash.
- Dip your toe into Visio Online
- Desktop or Laptop? What’s your choice?
- Beware of Google’s .ZIP domain and password-embedded URLs
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2023 by AskWoody Tech LLC. All Rights Reserved.