
FrankG.82553 (Customer) asked a question.
We have an "Allowed Geographic Regions", which only contains USA and Canada. In recent days, our several users were locked-out. From system log, there are many failed login attempts from other countries. I wonder if those login attempts from blocked IP are accounted to lockout accounts? It shouldn't be, right?

Hi Frank,
All login attempts count towards the lockout counter; the sign-on policies will only be applied after a successful login and will not stop accounts being locked-out.
If you want to prevent access for unwanted IPs you can use blacklist zones
https://support.okta.com/help/s/article/How-do-I-blacklist-an-entire-IP-Zone
Frank, I don't think so. The ONLY way I found to stop even the initial attempt was to use the blacklist checkbox when you define your geo-locations. Since I wanted to allows only the US and block everything else, a white-list would have been better but I was only able to get it to work by adding every other country in the world and blacklisting them. Crude but (mostly) effective.