Re: Account Lockout Policies



"Bogwitch" <Bogwitch@xxxxxxxxxxxxxxxxxxx> wrote in message
news:J7DBi.47020$1G1.30781@xxxxxxxxxxxxxxxxxxxxxxx
Roger Abell [MVP] wrote:

[snip]

Perhaps your more direct option would be to adjust the days of nonuse
and password change intervals so they are the same, and then nightly
read accounts with expired passwords and verify they are disabled.

Roger,

Slight flaw there. Imagine a user who last used the system just before the
password change reminder. Let's assume 14 days. Now, that user will have
an expired password in 14 days, not 30 days. Now remember that most users
(IMO) won't change their password until they absolutely positively have
to....

Bogwitch.

Well observed Bogwitch, and stated.
The solution to poster's is either being overlooked
or it is even more deeply messy, as you show.

One's nightly process would need to track the age
of first expiry of the pwd, disabling only upon an
uninterrupted 16 days (per your example) in expired
pwd state, so it is soluble. The use of this delay
counter might even work with the need to adjust the
"lockout" threshold and the pwd aging settings
(age and prewarn) toward each other. But still,
needing to persist info, being no longer a stateless
simple script, raises the bar for the nightly's code.

Good catch; thanks.

Is there really no direct, reliable, way to determine
accounts qualifying for the poster's scenario ?

Roger


.



Relevant Pages

  • Re: Account Lockout Policies
    ... read accounts with expired passwords and verify they are disabled. ... Imagine a user who last used the system just before the password change reminder. ...
    (microsoft.public.security)
  • Re: Mass change passwords on service and scheduled tasks
    ... Policy #2: We will force a password change of maintanence accounts that do ... Then SOX auditors would expect you to follow these policies. ...
    (microsoft.public.win2000.networking)
  • RE: user accounts expire
    ... Although password change frequency is a domain wide setting, ... the actual change is dependent on the users' accounts themselves, ... Do you have contractors or vendors assigned accounts configured this ...
    (microsoft.public.win2000.active_directory)
  • Re: local passwords mysteriously changed on several networked comp
    ... > machines it appears that there has not been a password change near ... resource kit that can remotely mass-modify user accounts. ...
    (microsoft.public.win2000.networking)
  • Re: Secure Channel Password
    ... I knew that the default is to provide membership safeguard by ... retaining machine account passwords two deep, ... such a disabling, then the mechanism could not be blind to the ... > that if it computer misses the password change interval twice the domain ...
    (microsoft.public.win2000.security)