cancel
Showing results for 
Search instead for 
Did you mean: 
sidharth.govil
Level 3
Status: Not Planned
We need the ability to log user unsuccessful login attempts into the Blue Prism platform audit logs.
Presently, while we can see all successful login / logoff attempts, unsuccessful login attempts are not logged.

As confirmed by the BP support team such a capability does not exist today.

Since this shortcoming is raised as a non-compliance from a security audit pov, appreciate that the unsuccessful login attempt audit functionality is included in the next BP release.
8 Comments
MeliktugOzden
Level 2

We can see succesful login in audit logs but there is no records for failed login.

 

For example, when i entered my password incorrectly i cannot login BP but after this failed login there is no record added to audit logs modüle.

 

We would like to see this kind of login attempt. Is there any possible way to check these?

Aprreciate your support on this issue.

Amy_T
Community Team
Community Team

Hi Meliktug, 
Thank you for sharing your idea. We've identified that your idea is a duplicate of another idea: https://community.blueprism.com/content/ideas/viewidea?IdeationKey=C041E0CA-A1C8-40BE-A04B-ABAB44DE5793

This older idea currently has 13 votes and when an idea reaches 15 votes it will be reviewed by our internal idea review team, so please give the other idea an upvote to get it seen quicker. 

Many thanks,
Amy

Amy_T
Community Team
Community Team

Hi Sidharth, 

Thanks for submitting your idea. The team have reviewed it and decided it's a good idea to explore further. As such, we've marked it as reviewed. Please pop back again in the future to check on how your idea progresses. 

All the best,

Amy

This is also an issue we have in our organisation.

We cant review failed Logins, even in BP7 nor Hub.

Successful Logins are also only logged when the Logins are done on a Resource Machine, not if you Login from a Client that doesnt start a Resource.

Due to having our BluePrism Production Environment in SOX Scope, it makes it even more worse to document Logins for an Audit - because in short words - we cant provide this Informations.

kuriachan
Level 2

Dear BP support team, @Amy_T 

Could you please update the progress status of idea - Failed login audit log entries.

 

Amy_T
Community Team
Community Team

Hi @kuriachan I've asked the product management team for an update and someone will be able to reply when they can. 

kuriachan
Level 2

hi @Amy_T Could you please provide status update from product management team.

Status changed to: Not Planned

Hello @sidharth.govil (and @kuriachan),

Thanks for taking the time to raise an idea.

Having reviewed the suggestion and discussed with our development teams, it's been pointed out that we already have the ability to log unsuccessful logins when they occur through Hub's Authentication Server, which is a key part of the Blue Prism ecosystem from v7.0 onwards as it allows access to the Blue Prism API as well as various other Hub plugins, such as the Hub Control Room.

In the event of a native user attempting to log in unsuccessfully via Authentication Server, a log will be created. Likewise if a disabled Active Directory user attempts to log into the product, a log would be created.  

Given this capability exists in Hub/Authentication Server already, I can confirm that at this time we don't intend to provide this capability as part of the in-built authentication mechanisms that exist in Blue Prism Enterprise as part of the future roadmap - instead users who require this capability are encouraged to consider deploying Hub and integrating Blue Prism Enterprise with Authentication Server to see this outcome achieved.

As a result of this update, I've gone ahead and added "in BPE" to the idea title (as this is what the idea is specifically referring to) and I'm going to move the idea into a Not Planned status.

Regards,

Rob