Clear a local user's brute-force protection block

Black Duck Portal documentation

How to clear a brute-force protection block from a local user's account so they can sign in again.

To minimize the risk of brute-force attacks, Black Duck Portal automatically blocks users from signing in after 10 unsuccessful sign-in attempts. Blocked users cannot sign in to Black Duck Portal until the block is removed. Blocks automatically expire 30 days after the last failed sign-in attempt.

When a security block is applied, Black Duck Portal sends the user an email with a link they can use to unblock their account. The user can also unblock their account by resetting their password (via Reset password on the sign-in page).

If a user cannot unblock their own account, an Organization Admin can clear the user's block. To do so, follow these steps:

Note: Only Organization Admins can clear blocks for other users.
  1. In Black Duck Portal, go to Org Admin > Users.
  2. Locate the blocked user.
    Tip: Use the Search Users... field to search by first name, last name, or email address.
  3. Select the options icon in the user's row, and then select Manage Security Blocks.
    The Security Blocks window opens.
  4. Select Clear Blocks.

The block is cleared and the user can sign in again.