Skip to main content

Account lockout after failed sign-in attempts

What happens after repeated failed sign-ins, and how to get access back.

RePro locks an account after a number of consecutive failed sign-in attempts. This protects accounts against someone guessing a password, and it applies to every account on the platform.

The lock does not clear on its own. There is no waiting period, and the person who is locked out cannot clear it themselves. An Organisation Admin can unlock the account from the Organisation’s user list in the RePro web app, and RePro Support can also clear it.

A completed sign-in clears the count, so someone who mistypes a password a few times and then gets it right is unaffected. On an account with two-factor authentication, the count clears once the second step is complete as well.

If you are locked out, ask your Organisation Admin to unlock your account. If you are not sure who that is, or nobody is available, contact RePro Support with the email address on the account.

What this means for a production

Two things are worth planning for before a shoot rather than discovering during one.

The lock applies to the account, not to whoever was typing. RePro counts failed attempts against the account being signed in to, not against the device or network they came from. Failed attempts made by someone else also count towards the account’s lockout.

Plan for it the way you would plan for a lost password. For anything time-critical:

  • Make sure more than one person in the production has an account with the access needed, so a single lockout does not stop the session.

  • Know who your Organisation Admins are, so someone on the production can clear a lock without waiting on Support.

  • If a viewer reports repeated sign-in failures, ask them to stop rather than keep trying, and get the account unlocked.

If you use Okta

Signing in through Okta OIDC or Okta SAML clears the failed-attempt count in the same way a completed password sign-in does.

Management Lockout

Management Lockout signs an administrator out after a period of inactivity and asks them to sign in again. It is separate from account lockout after failed sign-in attempts.

Did this answer your question?