Product manual
32
When authenticating OTPs, a user has 10 opportunities to enter an incorrect OTP. On the 11th failed OTP, a user's 2FA gets locked.
This is to prevent brute force guessing of OTPs. When a user's 2FA is locked, a red flag is displayed:
If it has been confirmed that the user's identity is not under attack, clicking on the Unlock 2FA button will unlock the user's 2FA.