> For the complete documentation index, see [llms.txt](https://ztrust.gitbook.io/ztrust-documentation/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ztrust.gitbook.io/ztrust-documentation/user-manual-ztrust-v1.0/admin-manual/how-to-set-up-brute-force-detection-feature.md).

# How to set up Brute Force Detection feature

This feature enables ZTrust to detect brute force attacks, where attackers use trial and error techniques to discover correct credentials. ZTrust can identify and prevent such unauthorized access attempts. In case of detection, customized notification emails are sent to the IT Security Team or System Administrator whenever multiple failed attempts originate from a single IP Address.

Steps to be followed to set up Brute Force Detection feature -

1. Go to Realm Settings.

![](https://lh7-us.googleusercontent.com/docsz/AD_4nXfmA1R0KndCVEffADr-mhRnGxQ8P5c9p04VlPNZ10rgI3g7NUVbV4_YFV9ArO3uV8eTTlkwR-s0Gjn0vT4VxllQ3Ty92XmRGiAmzbQHR5Lm_k6SyKcQSuz7Qag3ZM4SZnot_1CUpaMMndHdtY9Rl6Cz8Zxzbzp4rcxBMNbAbT36dvlUYJ5MSEI?key=trHzRgGTD4ANqZgrt456QA)

2. Click on Security Defenses.

<figure><img src="https://lh7-us.googleusercontent.com/docsz/AD_4nXezpdeKXRTOlGoBz3Tn4Q4NiGC1YNOsZiVp5YMduvq9Rs410ppcARjMzYKe4rdpkdJoM0W2CBypgNq43THne3eSNkH81hdr6oBxfpsidpkrwj0vqDzWUZU2G3mWfmYzfK5WLCcPV_TFk5a2WbsgCfHK7UXBXbdKbbfgqUYa3URgeOgRv0lmHLA?key=trHzRgGTD4ANqZgrt456QA" alt=""><figcaption></figcaption></figure>

3. Click on Brute Force Detection.
4. Turn the toggle button to ON.

<figure><img src="https://lh7-us.googleusercontent.com/docsz/AD_4nXdcSwddFzXxbRiJjlWxeqlWh5TASBL0CBbGT0rMvZAmQvNcUdySEgqKOMuuQ5VzXx5GjnkFJjZbfL7cfDIOWauxM1nMfL_shlthlD1P_li_grVrInWjfN_n1TwoICEaCIMKa44iWU3sDvoAue-8pCABfV5Gu0c9VEuFfrQnq8rc7sn32ir20tk?key=trHzRgGTD4ANqZgrt456QA" alt=""><figcaption></figcaption></figure>

<table><thead><tr><th width="132">Field Name</th><th width="188">Mandatory (Yes/No)</th><th width="109">Field Type</th><th>Description</th></tr></thead><tbody><tr><td>Enabled</td><td>Yes</td><td>Toggle</td><td>Enable/Disable the Brute Force Detection feature as required</td></tr></tbody></table>

<figure><img src="https://lh7-us.googleusercontent.com/docsz/AD_4nXfLnopCuDMyaR95ugoeysFxB4AkJXaTMsPKyGxJ89KG3rLJsM4HgYPPFdeFg_cCZQXm1LGTu7qm7ua5gKZaT2sGY-l24OXuHnYWld_FLrW4ePW-rhwSFOjICKBeSDq7Sl9UnzUdyLH_ADe3tMwWlSAtEQMGcrStNa8vzlLGnCnWGY2ctmfn15g?key=trHzRgGTD4ANqZgrt456QA" alt=""><figcaption></figcaption></figure>

5. Provide the details for the following according to your organization standards -

<table><thead><tr><th width="143">Field Name</th><th width="186">Mandatory (Yes/No)</th><th width="128">Field Type</th><th>Description</th></tr></thead><tbody><tr><td>Permanent Lockout</td><td>No</td><td>Toggle</td><td>If enabled, it permanently locks the user after reaching the maximum number of login attempts until the admin allows the user to attempt login again.</td></tr><tr><td>Max Login Failures</td><td>Yes</td><td>Text</td><td>Maximum number of login attempts permitted for a user if incorrect credentials are provided.</td></tr><tr><td>Wait Increment</td><td>Yes</td><td>Text</td><td>Duration after which the account will be unlocked to enable the user to log in again after the maximum number of failed attempts</td></tr><tr><td>Quick Login Check Milliseconds</td><td>Yes</td><td>Text</td><td>Recommended to verify if the login attempts are not from a bot. The time elapsed between the first failed login and the second failed login.</td></tr><tr><td>Minimum Quick Login Wait</td><td>Yes</td><td>Text</td><td><p>It represents the waiting period or the duration the user must wait after a rapid login failure.</p><p><br></p></td></tr><tr><td>Max wait</td><td>Yes</td><td>Text</td><td>Time after which it allows logging in again in case of a quick login failure.</td></tr><tr><td>Failure Reset Time</td><td>Yes</td><td>Text</td><td>Duration after which the count of failed login attempts will be reset to zero</td></tr></tbody></table>

All the above mentioned details are customizable and can be adjusted to align with the organization's standards.

6. Click on Save.

The Brute Force Detection feature will now be enabled.

<br>
