FAQ › Administration

Does Redmine have a feature that automatically locks an account after failed login attempts?

Created on 2026-01-30  •  ISHIHARA Yukiko

Redmine does not have a feature that automatically locks an account based on the number of failed login attempts.

In general, an account lock feature based on failed logins has a weakness. A malicious third party can repeat failed attempts with a specific user ID. In this way, the third party can intentionally prevent the legitimate user from logging in (a denial-of-service attack).

Measures to prevent unauthorized logins

To prevent unauthorized logins caused by guessed or leaked passwords, we recommend that you require two-factor authentication for all users.

Redmine supports two-factor authentication. When you make two-factor authentication required, an unauthorized login becomes very difficult in practice even if a password is leaked. The attacker must also obtain the one-time password that is shown on a device that the user owns, such as a smartphone.