| 1.2 PHTN-40-000004 | CIS VMware vSphere 8.0 vCenter Appliance Photon OS 4.0 STIG v1.0.0 CAT II | Unix | ACCESS CONTROL |
| 1.2 VCSA-80-000023 | CIS VMware vSphere 8.0 vCenter STIG v1.0.0 CAT II | VMware | ACCESS CONTROL |
| 1.4 EX19-ED-000019 | CIS Microsoft Exchange 2019 Edge Server STIG v1.0.0 CAT II | Windows | ACCESS CONTROL |
| 1.7 CISC-ND-000150 | CIS Cisco NX OS Switch NDM STIG v1.1.0 CAT II | Cisco | ACCESS CONTROL |
| 1.44 ALMA-09-007500 | CIS Cloud Linux AlmaLinux OS 9 STIG v1.0.0 CAT II | Unix | ACCESS CONTROL |
| 1.45 ALMA-09-007610 | CIS Cloud Linux AlmaLinux OS 9 STIG v1.0.0 CAT II | Unix | ACCESS CONTROL |
| 1.46 ALMA-09-007720 | CIS Cloud Linux AlmaLinux OS 9 STIG v1.0.0 CAT II | Unix | ACCESS CONTROL |
| 1.46 WN10-AC-000010 | CIS Microsoft Windows 10 STIG v1.0.0 CAT II | Windows | ACCESS CONTROL |
| 1.47 ALMA-09-007940 | CIS Cloud Linux AlmaLinux OS 9 STIG v1.0.0 CAT II | Unix | ACCESS CONTROL |
| 1.48 ALMA-09-007830 | CIS Cloud Linux AlmaLinux OS 9 STIG v1.0.0 CAT II | Unix | ACCESS CONTROL |
| 1.49 WN16-AC-000020 | CIS Microsoft Windows Server 2016 STIG v4.0.0 DC CAT II | Windows | ACCESS CONTROL |
| 1.49 WN16-AC-000020 | CIS Microsoft Windows Server 2016 STIG v4.0.0 MS CAT II | Windows | ACCESS CONTROL |
| 1.49 WN19-AC-000020 | CIS Microsoft Windows Server 2019 STIG v4.0.0 MS CAT II | Windows | ACCESS CONTROL |
| 1.49 WN19-AC-000020 | CIS Microsoft Windows Server 2019 STIG v4.0.0 DC CAT II | Windows | ACCESS CONTROL |
| 1.50 WN22-AC-000030 | CIS Microsoft Windows Server 2022 STIG v3.0.0 DC CAT II | Windows | ACCESS CONTROL |
| 1.60 PHTN-40-000194 | CIS VMware vSphere 8.0 vCenter Appliance Photon OS 4.0 STIG v1.0.0 CAT II | Unix | ACCESS CONTROL |
| 1.397 OL09-00-003010 | CIS Oracle Linux 9 STIG v1.0.0 CAT II | Unix | ACCESS CONTROL |
| 1.398 OL09-00-003011 | CIS Oracle Linux 9 STIG v1.0.0 CAT II | Unix | ACCESS CONTROL |
| 1.399 OL09-00-003012 | CIS Oracle Linux 9 STIG v1.0.0 CAT II | Unix | ACCESS CONTROL |
| 1.402 OL09-00-003022 | CIS Oracle Linux 9 STIG v1.0.0 CAT II | Unix | ACCESS CONTROL |
| 1.403 OL09-00-003023 | CIS Oracle Linux 9 STIG v1.0.0 CAT II | Unix | ACCESS CONTROL |
| 4.002 - Number of allowed bad-logon attempts does not meet minimum requirements. | DISA Windows Vista STIG v6r41 | Windows | ACCESS CONTROL |
| AIOS-01-080005 - Apple iOS must not allow more than 10 consecutive failed authentication attempts. | AirWatch - DISA Apple iOS 10 v1r3 | MDM | ACCESS CONTROL |
| AIOS-18-006900 - Apple iOS/iPadOS 18 must be configured to not allow more than 10 consecutive failed authentication attempts. | AirWatch - DISA Apple iOS/iPadOS 18 v2r3 | MDM | ACCESS CONTROL |
| ARBA-ND-000214 - AOS must be configured to enforce the limit of three consecutive invalid login attempts, after which time it must block any login attempt for 15 minutes. | DISA HPE Aruba Networking AOS NDM STIG v1r1 | ArubaOS | ACCESS CONTROL |
| AZLX-23-002420 - Amazon Linux 2023 must automatically lock an account when three unsuccessful logon attempts occur. | DISA Amazon Linux 2023 STIG v1r3 | Unix | ACCESS CONTROL |
| ESXi: esxi-8.account-lockout | VMware vSphere Security Configuration and Hardening Guide | VMware | ACCESS CONTROL |
| FGFW-ND-000045 - The FortiGate device must enforce the limit of three consecutive invalid logon attempts, after which time it must lock out the user account from accessing the device for 15 minutes | DISA Fortigate Firewall NDM STIG v1r4 | FortiGate | ACCESS CONTROL |
| GEN000460 - The system must disable accounts after three consecutive unsuccessful login attempts. | DISA AIX 5.3 STIG v1r2 | Unix | ACCESS CONTROL |
| GOOG-15-006400 - Google Android 15 must be configured to not allow more than 10 consecutive failed authentication attempts. | MobileIron - DISA Google Android 15 COPE STIG v1r5 | MDM | ACCESS CONTROL |
| GOOG-16-006400 - Google Android 16 must be configured to not allow more than 10 consecutive failed authentication attempts. | MobileIron - DISA Google Android 16 COBO STIG v1r3 | MDM | ACCESS CONTROL |
| GOOG-16-006400 - Google Android 16 must be configured to not allow more than 10 consecutive failed authentication attempts. | AirWatch - DISA Google Android 16 COPE STIG v1r1 | MDM | ACCESS CONTROL |
| GOOG-16-006400 - Google Android 16 must be configured to not allow more than 10 consecutive failed authentication attempts. | MobileIron - DISA Google Android 16 COPE STIG v1r1 | MDM | ACCESS CONTROL |
| KNOX-07-000600 - The Samsung Android 7 with Knox must be configured to not allow more than 10 consecutive failed authentication attempts. | AirWatch - DISA Samsung Android 7 with Knox 2.x v1r1 | MDM | ACCESS CONTROL |
| MOTO-09-000500 - The Motorola Android Pie must be configured to not allow more than 10 consecutive failed authentication attempts. | MobileIron - DISA Motorola Android Pie.x COBO v1r2 | MDM | ACCESS CONTROL |
| MOTO-09-000500 - The Motorola Android Pie must be configured to not allow more than 10 consecutive failed authentication attempts. | AirWatch - DISA Motorola Android Pie.x COPE v1r2 | MDM | ACCESS CONTROL |
| MSFT-11-000500 - Microsoft Android 11 must be configured to not allow more than 10 consecutive failed authentication attempts. | AirWatch - DISA Microsoft Android 11 COBO v1r2 | MDM | ACCESS CONTROL |
| OL09-00-003010 - OL 9 must configure SELinux context type to allow the use of a nondefault faillock tally directory. | DISA Oracle Linux 9 STIG v1r5 | Unix | ACCESS CONTROL |
| OL09-00-003011 - OL 9 must configure the use of the pam_faillock.so module in the /etc/pam.d/system-auth file. | DISA Oracle Linux 9 STIG v1r5 | Unix | ACCESS CONTROL |
| OL09-00-003012 - OL 9 must configure the use of the pam_faillock.so module in the /etc/pam.d/password-auth file. | DISA Oracle Linux 9 STIG v1r5 | Unix | ACCESS CONTROL |
| OS10-NDM-000120 - The Dell OS10 Switch must be configured to enforce the limit of three consecutive invalid logon attempts, after which time it must block any login attempt for 15 minutes. | DISA Dell OS10 Switch NDM STIG v1r1 | Dell_OS10 | ACCESS CONTROL |
| PHTN-40-000192 - The Photon operating system must be configured to use the pam_faillock.so module. | DISA VMware vSphere 8.0 vCenter Appliance Photon OS 4.0 STIG v2r1 | Unix | ACCESS CONTROL |
| PHTN-40-000193 - The Photon operating system must prevent leaking information of the existence of a user account. | DISA VMware vSphere 8.0 vCenter Appliance Photon OS 4.0 STIG v2r1 | Unix | ACCESS CONTROL |
| RHEL-08-020012 - RHEL 8 must automatically lock an account when three unsuccessful logon attempts occur during a 15-minute time period. | DISA Red Hat Enterprise Linux 8 STIG v2r7 | Unix | ACCESS CONTROL |
| RHEL-08-020013 - RHEL 8 must automatically lock an account when three unsuccessful logon attempts occur during a 15-minute time period. | DISA Red Hat Enterprise Linux 8 STIG v2r7 | Unix | ACCESS CONTROL |
| RHEL-08-020025 - RHEL 8 must configure the use of the pam_faillock.so module in the /etc/pam.d/system-auth file. | DISA Red Hat Enterprise Linux 8 STIG v2r7 | Unix | ACCESS CONTROL |
| RHEL-09-411105 - RHEL 9 must ensure account lockouts persist. | DISA Red Hat Enterprise Linux 9 STIG v2r8 | Unix | ACCESS CONTROL |
| RHEL-09-611030 - RHEL 9 must configure the use of the pam_faillock.so module in the /etc/pam.d/system-auth file. | DISA Red Hat Enterprise Linux 9 STIG v2r8 | Unix | ACCESS CONTROL |
| vCenter: vcenter-8.administration-sso-lockout-policy-max-attempts | VMware vSphere Security Configuration and Hardening Guide | VMware | ACCESS CONTROL |
| WN22-AC-000030 - Windows Server 2022 must have the period of time before the bad logon counter is reset configured to 15 minutes or greater. | DISA Microsoft Windows Server 2022 STIG v2r8 | Windows | ACCESS CONTROL |