turbot/steampipe-mod-azure-compliance

Query: ad_account_lockout_threshold_max_10

Usage

powerpipe query azure_compliance.query.ad_account_lockout_threshold_max_10

SQL

with distinct_tenant as (
select
distinct tenant_id,
display_name,
subscription_id,
_ctx
from
azure_tenant
)
select
id as resource,
case
when (value)::int <= 10 then 'ok'
else 'alarm'
end as status,
case
when value is null then t.display_name || ' lockout threshold not configured.'
else t.display_name || ' lockout threshold set to ' || value || '.'
end as reason,
t.tenant_id
from
distinct_tenant as t,
azuread_directory_setting
where
name = 'LockoutThreshold';

Controls

The query is being used by the following controls: