DDOS ACCOUNT LOCKOUT PROTECTION FOR SKYPE-FOR-BUSINESS
Prevent account lockout attacks before they reach Active Directory
Active Directory can lock accounts after several failed login attempts. Attackers can exploit this by using known usernames to lock individual accounts or script attacks that lock users across the network.
SphereShield provides DDoS account lockout protection for Skype for Business by auditing failed attempts, detecting attacks, and applying soft lockout protection in the DMZ.
-
Stop simple username-based scripting attacks from causing business downtime.
-
Protect multiple protocols, methods, channels, and locations from one unified defense layer.
-
Use device pre-authentication so only registered devices reach Active Directory.
SphereShield soft lockout in the DMZ
Active Directory security policies can lock accounts after several failed attempts. If an attacker knows a username, they can trigger lockout without needing the correct password.
Attackers can automate this process and lock many users across the network, causing business downtime for all network systems, not only Skype for Business.
Generic account lockout protections often fail to fully protect Skype for Business because the attack surface spans multiple protocols, methods, channels, and global locations.
HTTPS and SIP exposure.
Basic, NTLM, and SOAP authentication.
Sign in, meetings, web API, and Exchange.
EMEA, US, and APAC environments.
Unified defense for Skype for Business authentication exposure
Failed attempt auditing
All failed login attempts are audited so attack activity can be detected and reviewed.
Soft lockout in the DMZ
When an attack is detected, protection is activated in the DMZ before requests can impact Active Directory.
Unified protection
Protect protocols, methods, channels, and locations with a single defense approach.
Device pre-authentication
Only authentication requests from registered devices are allowed to reach Active Directory.
Script attack prevention
Reduce the risk of basic username scripts locking large groups of network accounts.
Defend exposed authentication services against user enumeration
SphereShield Tarpit protects Skype for Business against enumeration attacks aimed at exposed authentication services, including Webticket NTLM, SOAP, OAuth, and the unauthenticated Lyncdiscover service.
The Tarpit delays failed authentication attempts and relevant communication so server response times do not reveal whether a submitted username exists.
System administrators can fine-tune delay behavior to match real-world Skype for Business on-premises response times.
Users with correct credentials remain unaffected when this feature is active.
SphereShield Credentials
Provides broader protection against user enumeration and other potential vulnerabilities.
No exposed Windows Authentication
Deployments using SphereShield Credentials do not expose Windows Authentication interfaces to the internet.
Dedicated Skype for Business password
Users can create a dedicated external Skype for Business password that is different from their Active Directory password.
Already protected
Customers already using SphereShield Credentials are already protected against user enumeration attacks.
Protect against account lockout attacks caused by repeated failed login attempts.
Activate soft lockout in the DMZ when attack behavior is detected.
Audit all failed login attempts.
Defend across protocols, methods, channels, and locations.
Require registered device pre-authentication before requests reach Active Directory.
Delay failed authentication attempts to reduce user enumeration risk.
Protect Skype for Business authentication from lockout attacks, scripted login storms, and user enumeration attempts before they impact Active Directory.
Secure Your Collaboration Environment
Protect Microsoft 365, Webex, Teams, OneDrive, SharePoint, and Skype for Business with SphereShield’s policy-driven security, compliance, and governance controls.