is there an existing function that allows the administrators to enforce a rule that after multiple failed login attempts by a user, that that user's account becomes "locked", and is only unlock-able by the administrator?
I know that there is an existing solution that after X number of failed attempts, a Captcha is required, but I was hoping for a "full account lock" solution if possible.