RE: Windows 2000 password policy

From: Jim Barrett (jimb_at_ins.com)
Date: 06/24/03

  • Next message: David Stevens: "RE: Windows 2000 password policy"
    To: "'Chris Carlson (OTG)'" <ccarls@microsoft.com>, "'hong li'" <hong_li_98@yahoo.com>, <focus-ms@securityfocus.com>
    Date: Tue, 24 Jun 2003 07:58:50 -0400
    
    

    Okay, I stand corrected on that issue, but realistically I have never
    seen that sort of thing in the real world. One generally does not make
    a system part of the domain and then use local accounts to access it.

    One of the first things that I look for on a security audit is local
    accounts on critical systems. Besides the required administrator
    account, the only local accounts on a machine should be service accounts
    required by an application running on that box that for some reason or
    other cannot use a domain based system account.

    One could also make the argument that you need local accounts to work on
    the system should connectivity to the domain controller be severed due
    to a faulty WAN link. In that instance, since W2K machines cache local
    credentials, a user can still log onto a system with no connectivity to
    the domain provided that they have successfully logged on there before.
    Additionally, if access to the system is critical, then a local DC can
    provide the necessary fault tolerance.

    Local accounts are much easier to compromise than domain accounts, thus
    my recommendation is to strictly limit them. As for the necessary
    administrator account, while password policies can be applied,
    generally, users will exempt the administrator account from regular
    password changes, and account lockout cannot be applied to the built-in
    administrator.

    Jim Barrett, MCSE, CISSA, CISSP, CCNP
    Principal Consultant
    International Network Services
    Boston, MA

    -----Original Message-----
    From: Chris Carlson (OTG) [mailto:ccarls@microsoft.com]
    Sent: Tuesday, June 24, 2003 2:23 AM
    To: Jim Barrett; hong li; focus-ms@securityfocus.com
    Subject: RE: Windows 2000 password policy

    >You will see the options for setting password policy in the OU GPO, but
    >changes there will not affect anything.

    I wouldn't necessarily say that, password policies at the OU level still
    apply to the local security accounts.
    http://support.microsoft.com/default.aspx?scid=kb;en-us;255550

    -Chris

    -----------------------------------------------------------------------------
    ------------------------------------------------------------------------------


  • Next message: David Stevens: "RE: Windows 2000 password policy"

    Relevant Pages

    • Re: Password "security" - was"Passwords with Lan Manager (LM) under Windows" and
      ... using local accounts, one could easily boot to an alt OS and replace the SAM ... since the local admin owns the EFS ... > Regarding laptop security, you're in the same boat as the rest of us. ...
      (Pen-Test)
    • RE: Group Policy: multiple password policies in the same domain?
      ... > Domain Wide Password policies cannot be blocked by OU ... Someone else mentioned that it would only affect local accounts (local ... whatever password policy the domain controllers were given would ...
      (Focus-Microsoft)
    • Re: Multiple Applications on TS
      ... Why on earth would you want to maintain local accounts, ... MCSE, CCEA, Microsoft MVP - Terminal Server ... > server,the group policy is not in effect.Is group policy meant ...
      (microsoft.public.windows.terminal_services)
    • Re: External Trust - Cant see share contents
      ... Use the universal groups to configure the share access permissions. ... Windows Server 2003 Domain with an External Trust to the remote ... are Share = Local group with local accounts have Change. ...
      (microsoft.public.windows.server.active_directory)
    • Re: Default Domain Policy - Password Chg 90 days
      ... Mathieu CHATEAU ... There are certain accounts that have ... Or is it used for local accounts ... > user - it is NOT being done through local GPOs. ...
      (microsoft.public.windows.server.active_directory)