Disabling bruteforce protection should not been taken as a solution, this is just removing warnings. There are two possibilities why that happens, if you are lucky you have a misconfigured client or app that uses wrong credentials and triggers the protection, or, if you are not so lucky, there is a bruteforce attack going on, in that case you have just enabled the attacker to permanently try different passwords until he finds his way in, without the timeconsuming protection. So better find out what is triggering that.