
DanM.34740 (Customer) asked a question.
HealthInsight tells me I have a weak policy:
- Active Directory Policy is missing: lockout after unsuccessful attempts.
Except I go to this policy and there is no option to enable this option. The only lockout option is 'show lock out failures'. The default policy has this option but not the Active Directory Policy.
Am I missing something or is this a bug in HealthInsight?

There should be three checkboxes in the Lock out section of your Active Directory password policy, including the one that HealthInsight is referring to.
I get that same warning from HealthInsight, but I ignore it because my Okta tenant is configured to delegate authentication to AD, and I want AD to control the user's account lockout state. In the past, I tried enabling this option in Okta but it actually caused more confusion for our Help Desk team because they needed to check for account lockouts in two locations (Okta AND Active Directory).
Yeah, I don't have that. Will log a ticket with Support. Thanks for the reply.