Account Lockout Duration catch 22?

From: CG (anonymous_at_discussions.microsoft.com)
Date: 05/04/04


Date: Mon, 3 May 2004 15:56:03 -0700

If I set Account Lockout Duration to 0 requiring an admin to unlock IDs…. What happens if all the admin accounts get locked? A malicious user, password-guessing worm, or even an admin running a security scanner that checks password of all the IDs in the domain, could do the trick. Am I correct in thinking that if this happens in a root domain it would be time to start over and completely rebuild?


Quantcast