password expiration policy for admin and system accounts ?

From: JJ (johnny_at_tamtam.com)
Date: 10/20/05

  • Next message: Imhotep: "Re: Windows chokes on latest Microsoft patch"
    Date: Wed, 19 Oct 2005 22:29:41 GMT
    
    

    Our auditors are objecting to our having Domain Administrator and domain
    system accounts with passwords that never expire.

    Yes, we change some of these passwords from time to time, but they're
    normally set to never expire.

    We are wondering about how other companies do it, since we've never heard of
    any IT Dept. that had such a policy, and we think the auditors are being
    unreasonable -- forcing password expiration on such accounts could be a
    logistical nightmare as it would cause critical services to stop running.

    We're not that big, but we do have about 30 servers and 200 users to
    support. There's only 1 Win2K domain, with Exchange 2K, SQL and other
    resource servers.

    Please post your experiences and opinions.

    Thanks.


  • Next message: Imhotep: "Re: Windows chokes on latest Microsoft patch"

    Relevant Pages

    • password expiration policy for admin and system accounts ?
      ... Our auditors are objecting to our having Domain Administrator and domain ... system accounts with passwords that never expire. ... Yes, we change some of these passwords from time to time, but they're ...
      (microsoft.public.win2000.security)
    • Re: How To Enabling a Password Policy
      ... > passwords is on the system configuration side not the ... limited testing running this on a Win2K Pro workstation to force admins ... to change their passwords over X days old (set on PDC). ... ::Avoid admins whose accounts are set never to expire. ...
      (microsoft.public.win2000.security)
    • Re: Group Policys and Passwords
      ... Either you have two separate domains or you are implementing it at a local ... There is only one pw policy per domain.... ... it's not a great idea to have all passwords expire the same day. ...
      (microsoft.public.windows.server.general)
    • Re: Password expirey
      ... Passwords expire based on the pwdlastset time being older than the current date minus the domain password policy. ... So yes, if you get all of the passwords expired and set in time, when you turn on the policy, no one will expire until their password age hits the date. ...
      (microsoft.public.windows.server.active_directory)
    • Re: Password expiration message?
      ... The FTP server userid is specifically non-TSO-enabled. ... a report of IDs with passwords about to expire, and for the ones that you care about you issue ALTUSER whatever-id PASSWORDNOEXPIRED ... Or, you make those IDs have non-expiring passwords, and change them at your convenience, rather than every normal interval of time. ... Or you use something like SFTP (provided on z/OS by OpenSSH) and its public/private key support to avoid password expiration. ...
      (bit.listserv.ibm-main)