RE: ADSI question

From: Free, Bob (RWF4_at_pge.com)
Date: 08/28/04

  • Next message: Laura A. Robinson: "RE: ADSI question"
    Date: Fri, 27 Aug 2004 16:26:30 -0700
    To: <focus-ms@securityfocus.com>
    
    

    There's also a very nice tool already written to expire them in batches-

    From http://www.joeware.net/win32/

    "Expire - This tools expires users that are listed in a tab delimited
    file. You can specify user's domain, id, and how old the password has to
    be to force a expiration (this is so that if someone just reset their
    password you don't force them to do it again). I had to write this due
    to a security breach in one of our divisions and I had to expire some
    150,000 user id's. I would like to recommend to anyone expiring a large
    percentage of their user's ID's at once do it in a staggered time frame
    so that you don't get yourself into a cycle of heavy password changing.
    We stretched our expires out over about 4 weeks and still saw very heavy
    password reset days." http://www.joeware.net/win32/zips/Expire.zip

    -----Original Message-----
    From: Renouf, Phil [mailto:Phil.Renouf@tdsecurities.com]
    Sent: Friday, August 27, 2004 1:43 PM
    To: focus-ms@securityfocus.com
    Subject: RE: ADSI question

    Another thing to keep in mind in that situation is that if you have a
    large number of users you don't want them all changing their password on
    the same day as that might cause some unneeded stress on your DCs. It
    will also mean that on the same day every 90 days (or whatever your
    setting is) everyone will be changing their passwords.

    Good advice :)

    Phil

    -----Original Message-----
    From: Ayers, Diane [mailto:DMA8@pge.com]
    Sent: Friday, August 27, 2004 1:40 PM
    To: focus-ms@securityfocus.com
    Subject: RE: ADSI question

    Just one comment to add. Depending on your environment, setting all
    accounts to change passwords on the next login all at the same time may
    not be the best approach. If you have a large user base, resetting all
    passwords as expired may overwhelm your help desk. An alternate
    approach would be to do your accounts in batches and spread the impact
    over a given time period.

    Set your policy to enforce complex passwords and then process the
    accounts in batches until you get all your accounts to have new
    passwords. We have used this process with good success.

    Diane

    ------------------------------------------------------------------------

    ---
    ------------------------------------------------------------------------
    ---
    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------
    

  • Next message: Laura A. Robinson: "RE: ADSI question"

    Relevant Pages

    • Re: Add multiple local user accounts
      ... user accounts to a PC and set their passwords to never expire. ... The trick is you must use the WinNT provider for local accounts. ... ' Bind to the local computer object. ... ' Create local user object. ...
      (microsoft.public.scripting.vbscript)
    • Re: Check the user account expire date
      ... Joe Kaplan-MS MVP Directory Services Programming ... Co-author of "The .NET Developer's Guide to Directory Services Programming" ... I have a quesiton about checking user account expire date. ... email that let me know which user accounts will be expired in a week. ...
      (microsoft.public.windows.server.active_directory)
    • Re: Password Expiration Question
      ... Password Age policy setting is enabled or not. ... attribute up to the current date for all accounts. ... This gives you some control over which accounts expire when. ...
      (microsoft.public.windows.server.security)
    • AD 2003 password expiration/complexity question
      ... if my domain policy says maximum password age is zero days (passwords never ... expire) and i change it to an arbitrary number, say 10, and all accounts are ...
      (microsoft.public.windows.server.active_directory)
    • Re: School district and creative way to handle student passwords ?
      ... Many students use their accounts once in a while. ... expire every 180 days. ... One of the complaints that it can be ...
      (microsoft.public.security)