RE: Password Policy

From: Tim - IBL (timv@iceburnslair.com)
Date: 08/23/02


From: "Tim - IBL" <timv@iceburnslair.com>
To: "'kawaii'" <trunks@stackers.org>, <security-basics@securityfocus.com>
Date: Fri, 23 Aug 2002 09:29:13 -0500

In win2k / active directory you can use group policies to rename and/or
change the local admin password for all machines in a particular OU.
Then whenever the group policy is set to propagate the local admin info
is updated.

-t

-----Original Message-----
From: kawaii [mailto:trunks@stackers.org]
Sent: Thursday, August 22, 2002 1:55 PM
To: security-basics@securityfocus.com
Subject: Password Policy

I am in a bit of a dilemma now and I was hoping to draw on the list's
knowledge.

I am in a small/mid size environment, and we are implementing a new
password
policy that requires passwords to be changed quarterly (90 days). Now,
that
works fine for our servers and networking equipment, but how do people
handle it for workstations?

Obviously, we can't go to every workstation and change the local admin
passwords every 90 days. (Well, we can, but it is a bother.) I assume
that
people out there have already worked through this problem and came up
with a
good system for doing this?

Thanks in advance!

Ever lovable and always scrappy,
kawaii

"Raise the Dour Roger!" - Rob



Relevant Pages

  • Re: "Undoing" the locking of a screensaver on WinXP.
    ... You need to ask your domain administrator to disable the policy for you - you can't do it yourself. ... Even if you're local admin, you can't just disable it, since the Group Policies get refreshed every 90-120 minutes by default. ...
    (microsoft.public.windows.group_policy)
  • local admin pwd change needed
    ... i'm on a win2k native domain with 2000pro workstations.. ... is there a policy or some way i can change all the local admin pwd's on all ...
    (microsoft.public.win2000.group_policy)
  • Group Policies - NT4.0 and W98
    ... I am a novice at group policies. ... with W98 and XP workstations. ... I need to set a policy so ...
    (microsoft.public.security)
  • Re: Restricted Groups...with exceptions
    ... one has a separate policy for access restrictions, IPSec, etc. ... now my requirement is certain users need local admin access to all PCs ... multiple sites and then I assume i'd need to manually add my global groups) ...
    (microsoft.public.win2000.group_policy)
  • Re: Securing Enterprise Policy from local admins
    ... permission on a local resource to be denied to a local admin by default. ... would be no way to prevent the change to the enterprise security policy. ... > security admins or domain admins can modify the enterprise policy. ...
    (microsoft.public.dotnet.security)

Quantcast