Most of the web services that require a login have a specified number of consecutive invalid login attempts allowed, after which you are restricted from further login attempts for a certain time ...
Do you guys still have this policy turned on? Does it do anything other than DoS attack forgetful users and consumer dozens of technician man-hours per ticket? I have it set for 1 minute and 3 minute ...