Policy enforcement- Admin accounts



In an active directory environment (windows 2003), I want to ensure lockout for administrator accounts also, in order to protect against attempts to brute force account password. The flipside is, we might have a DoS situation but I can live with it. Is there a tool I can deploy to ensure that admin account also locks out after certain no. of attemps?

Also, ONLY for admin accounts, I want to enforce certain settings like: Password should contain atleast 15 characters, should not contain a dictionary word etc.
My normal password policy for AD user accounts, set at the domain level is a minimum of 8 chars but I want to deploy this special policy of 15 chars minimum for admin accounts.

How should I go about this?



Relevant Pages

  • RE: Policy enforcement- Admin accounts
    ... GPO on an OU, so you can set a different password policy. ... Subject: Policy enforcement- Admin accounts ...
    (Security-Basics)
  • Re: Minimum password requirements
    ... but this is based on my experiences with a variety ... This would be all admin accounts, ... reason they want to change the password every day I'd let them. ... Ripper/etc to audit the passwords on admin accounts (which is a mixed ...
    (Security-Basics)
  • Welcome screen doesnt allow logins.
    ... I have only two accounts on my machine: Admin and a User account. ... When i logout of User or Admin accounts and get to the Welcome screen, ... The logon white boxes are there, but i cannot type my password inside of them. ...
    (microsoft.public.windowsxp.help_and_support)
  • Users cannot use printer/scanner/sound?
    ... accounts only in admin accounts, ... patched it for win2000 and it worked in admin mode) works ... compatibility cause the device not to work in user mode? ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Lost Administrative Privileges!
    ... so I went in to the recovery console to rename the ... SAM file, but I run in to the same problem....I need the ... even if one of these two accounts becomes ... >> admin accounts help me even in my current situation? ...
    (microsoft.public.win2000.networking)