Disabling risky services for any OS or software “out-of-the-box” is always a good idea. If you need it, then you or your system administrators can enable it.
A brute force attack is where a threat actor – or normally a threat actor computer – will try a range of different passwords against an account to see if one works. It can take a while, and many attempts, but if the user is using a useless password, the threat actor wins.
Windows 11 will now automatically lock user and administrator accounts after 10 failed sign-in attempts. The login will be blocked for 10 minutes.
Windows 11 now blocks RDP brute-force attacks by default (bleepingcomputer.com)
This comes at the same time Microsoft has enforced blocking of VBA macros from the internet in Office apps.
Clive Catton MSc (Cyber Security) – by-line and other articles