Re: User account - password attribute ?



I think your issue is with passwords that were set before the
policy on password strength was defined to be in force.
To get the old non-compliant passwords use a password
expiration and so after one pass through the expiration time
all account will have needed to reset their passwords, at which
time the policy will be enforced on them.

It is not my experience that an admin can set a password
that fails to meet the policy.

--
Roger Abell
Microsoft MVP (Windows Server : Security)

<John> wrote in message news:1s0nv1h88gfm4uufiqpgsdgjnen3n7p5tj@xxxxxxxxxx
Hi

A security audit in company states that a large amount of users are
allowed to use weak/zero passwords.

The domain policy setting says that weak/zero password isn't allowed!

Domain controllers : w2k3 and w2k

Here is the clue:
A closer look shows that a "weak/zero password user" can't make a weak
password by them self.
But an administrator CAN do it, by reseting the password. Have tried
that.

It seems to be users who have been auto-created / migrated who have
this "weak/zero password" possibility (old users - created for some
years ago).

On a newly created user couldn't even the administrator make a
weak/zero password for the user. This is normal.

Want to stop the possibility for setting weak/zero passwords by
helpdesk and administrator peoples.

Any idea about which user attribute to look for or ideas to solve this
behavior ?

Regards
John


.



Relevant Pages

  • Password policy & userAccountControl ?
    ... A security audit in company states that a large amount of users are ... The domain policy setting says that weak/zero password isn't allowed! ... A closer look shows that a "weak/zero password user" can't make a weak ...
    (microsoft.public.windows.server.active_directory)
  • Re: Password policy & userAccountControl ?
    ... To complement what Neil has stated: ... Users may have set their pw before the pw policy was defined ... A closer look shows that a "weak/zero password user" can't make a weak ... But an administrator CAN do it, ...
    (microsoft.public.windows.server.active_directory)
  • Re: Must all users be administrators?
    ... The familiar look of the AD objects tree you see in Group Policy Editor is ... This seems modestly confusing to an SBS Administrator because there's very ... those rights happen to be nearly unlimited. ... sit a workstation logged on as the Local Administrator, by default, there ...
    (microsoft.public.windows.server.sbs)
  • Re: The local policy of this system does not permit you to logon i
    ... Security policies were propagated with warning. ... Error 0x534 occurs when a user account in one or more Group Policy objects ... I have checked the security policies & the administrator profile is not ...
    (microsoft.public.windows.server.sbs)
  • Re: Administrator unable to log on Interactively
    ... Firstly i tried accessing the domain controller C drive ... I think the policy has been changed in the "local security ... >> administrator is not able to log on interactively. ... >Interactive Logon setting takes precedence over the Allow ...
    (microsoft.public.win2000.security)