You need to ensure that a record of failed logon attempts is retained for 90 days on all domain controllers