Skype Ddos Account Lockout Protection

DDOS ACCOUNT LOCKOUT PROTECTION FOR SKYPE-FOR-BUSINESS

Protect Skype for Business authentication from account lockout and user enumeration attacks with DMZ-based soft lockout, auditing, and device pre-authentication.
Account Lockout Protection
Account Lockout Protection

Prevent account lockout attacks before they reach Active Directory

Active Directory can lock accounts after several failed login attempts. Attackers can exploit this by using known usernames to lock individual accounts or script attacks that lock users across the network.

SphereShield provides DDoS account lockout protection for Skype for Business by auditing failed attempts, detecting attacks, and applying soft lockout protection in the DMZ.

  • Stop simple username-based scripting attacks from causing business downtime.

  • Protect multiple protocols, methods, channels, and locations from one unified defense layer.

  • Use device pre-authentication so only registered devices reach Active Directory.

Failed login storm

SphereShield soft lockout in the DMZ

Active Directory protected
Repeated failed attempts Audited
Attack pattern detected Soft lock
Registered device check Required
Defense actions
Audit
Soft lock
Defend
Pre-auth
The problem

Active Directory security policies can lock accounts after several failed attempts. If an attacker knows a username, they can trigger lockout without needing the correct password.

Attackers can automate this process and lock many users across the network, causing business downtime for all network systems, not only Skype for Business.

Generic account lockout protections often fail to fully protect Skype for Business because the attack surface spans multiple protocols, methods, channels, and global locations.

Multi-protocol

HTTPS and SIP exposure.

Multi-method

Basic, NTLM, and SOAP authentication.

Multi-channel

Sign in, meetings, web API, and Exchange.

Multi-location

EMEA, US, and APAC environments.

SphereShield solution

Unified defense for Skype for Business authentication exposure

Failed attempt auditing

All failed login attempts are audited so attack activity can be detected and reviewed.

Soft lockout in the DMZ

When an attack is detected, protection is activated in the DMZ before requests can impact Active Directory.

Unified protection

Protect protocols, methods, channels, and locations with a single defense approach.

Device pre-authentication

Only authentication requests from registered devices are allowed to reach Active Directory.

Script attack prevention

Reduce the risk of basic username scripts locking large groups of network accounts.

Tarpit protection

Defend exposed authentication services against user enumeration

SphereShield Tarpit protects Skype for Business against enumeration attacks aimed at exposed authentication services, including Webticket NTLM, SOAP, OAuth, and the unauthenticated Lyncdiscover service.

The Tarpit delays failed authentication attempts and relevant communication so server response times do not reveal whether a submitted username exists.

System administrators can fine-tune delay behavior to match real-world Skype for Business on-premises response times.

Users with correct credentials remain unaffected when this feature is active.

Additional protection

SphereShield Credentials

Provides broader protection against user enumeration and other potential vulnerabilities.

No exposed Windows Authentication

Deployments using SphereShield Credentials do not expose Windows Authentication interfaces to the internet.

Dedicated Skype for Business password

Users can create a dedicated external Skype for Business password that is different from their Active Directory password.

Already protected

Customers already using SphereShield Credentials are already protected against user enumeration attacks.

Highlights

Protect against account lockout attacks caused by repeated failed login attempts.

Activate soft lockout in the DMZ when attack behavior is detected.

Audit all failed login attempts.

Defend across protocols, methods, channels, and locations.

Require registered device pre-authentication before requests reach Active Directory.

Delay failed authentication attempts to reduce user enumeration risk.

Protect Skype for Business authentication from lockout attacks, scripted login storms, and user enumeration attempts before they impact Active Directory.

Secure Your Collaboration Environment

Protect Microsoft 365, Webex, Teams, OneDrive, SharePoint,
and Skype for Business with SphereShield’s policy-driven security, compliance, and governance controls.

Create your account