When the number of incorrect passwords for a user account exceeds the threshold, the user account is locked and an SECU_ALM alarm is reported, but the user account that has been used to log in to another terminal in will not be forced offline. After a user account is locked, you can query the operation logs and identify the terminal where the user account is used for login attempts based on the terminal information such as the IP address recorded in the operation logs.<?xml:namespace prefix = "o" ns = "urn:schemas-microsoft-com:office:office" />
From group: Transport&Access Network

