Symptoms
Audit log shows multiple User was blocked warnings with the following description:
<Username> was blocked due to ten failed sign-in attempts
User agent: 'Faraday v0.9.2'
Audit log tab shows that the failed logins came from IP in datacenter-internal 10.x.x.x network.
When one checks the events in the Audit log tab in the Management console at the tenant level where the respective cloud login was blocked, one can see parts of the event payload like:
InitiatorSystem
Initiator's tenant -
*IP 10.253.84.176
Method API
Description
_username_ was blocked due to ten failed sign-in attempts.
*User agent: 'Faraday v0.9.2'*
Cause
Issue in the server-side (cloud-side) components of the product: PLTFRM-34315.
Solution
This issue has been fixed in Acronis Cyber Protect Cloud 21.11.
Note that this warning only affected audit logs: incorrect warnings were generated. Users are not actually locked.