Re: Password Policy

From: James McGee (james__mcgee@hotmail.com)
Date: 08/25/02


From: "James McGee" <james__mcgee@hotmail.com>
To: "kawaii" <trunks@stackers.org>, <security-basics@securityfocus.com>
Date: Sun, 25 Aug 2002 21:34:50 +0100

http://www.pedestalsoftware.com/ntsec/scripts/index.htm

This URL gives a batch file that will do what you want.

I have not tried it though.....
----- Original Message -----
From: "James McGee" <james__mcgee@hotmail.com>
To: "kawaii" <trunks@stackers.org>
Sent: Sunday, August 25, 2002 9:21 PM
Subject: Re: Password Policy

> I would remove the local admin account, and add a Domain account into
local
> admins.
>
> Saves having to have a local admin..
>
> Cheers
>
> JM
> ----- Original Message -----
> From: "kawaii" <trunks@stackers.org>
> To: <security-basics@securityfocus.com>
> Sent: Thursday, August 22, 2002 7:54 PM
> Subject: Password Policy
>
>
> > I am in a bit of a dilemma now and I was hoping to draw on the list's
> > knowledge.
> >
> > I am in a small/mid size environment, and we are implementing a new
> password
> > policy that requires passwords to be changed quarterly (90 days). Now,
> that
> > works fine for our servers and networking equipment, but how do people
> > handle it for workstations?
> >
> > Obviously, we can't go to every workstation and change the local admin
> > passwords every 90 days. (Well, we can, but it is a bother.) I assume
that
> > people out there have already worked through this problem and came up
with
> a
> > good system for doing this?
> >
> > Thanks in advance!
> >
> > Ever lovable and always scrappy,
> > kawaii
> >
> > "Raise the Dour Roger!" - Rob
> >
>



Relevant Pages

  • Re: Domain Admin account and lockout Policy
    ... You deny read to an Admin, ... be able to read a userconfiguration, if it exist inside the GPO. ... wrong target -> no efect. ... Ok, Password policy is a little bit special, but the scenario you created ...
    (microsoft.public.windows.group_policy)
  • Ramifications of chaning admin password
    ... I've recently updated my password policy and as a result I updated my admin ... (backup jobs, scheduled tasks, etc.) ... I suppose one scenario is to not change ...
    (microsoft.public.windows.server.sbs)
  • RE: Gpedit.msc - password length greyed out
    ... You need to find whichever or program you used and access the Admin ... "nass" wrote: ... the option in the password policy). ... Then your admin account corrupted or your machine is infected, ...
    (microsoft.public.windowsxp.security_admin)
  • admin password
    ... Ia m running a win 2000 with AD and 100 users in a single domain. ... my admin password is not a strong pwd. ... Ia m planning to impose password policy for all my users in my domain. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Local device name is already in use error
    ... Ace, ... There is not batch file in that same properties page. ... Regarding the admin share: these workstations would not have a need ... But then it would happen to all workstations. ...
    (microsoft.public.win2000.active_directory)