Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: active directory password policy |
|---|---|
| Date: | Tue, 8 Feb 2005 13:30:22 -0500 |
We ran into the same problem. The only way I found to get around this is to set the 'password never expires' setting for all users using ADModify. This allows you to stagger who gets the policy when. This also allows you to exclude remote users. You can then control their password changes at your convenience. ADModify is a must. It works great. Just keep in mind that if you set the 'password never expires' (which will override the domain wide policy) you cannot also set 'user must change at next logon'. The two are mutually exclusive. Hope this helps. -----Original Message----- From: John Coke [mailto:JCoke@afsimage.com] Sent: Monday, February 07, 2005 7:01 PM To: Mike; William Stegman; focus-ms@securityfocus.com Subject: RE: active directory password policy Domain-wide password, account lockout and kerberos policies can only be set at the domain level. Password policies linked at the OU level are applied to the users configured on the local machine and are ignored when the users logs in with a domain account. -John -----Original Message----- From: Mike [mailto:mike_sha@shaw.ca] Sent: Monday, February 07, 2005 12:29 PM To: William Stegman; focus-ms@securityfocus.com Subject: RE: active directory password policy Could you put them in a different OU with it's own GP that has looser policies on password security? Mike Fetherston
-----Original Message----- From: William Stegman [mailto:stegmanw@comcast.net] Sent: Friday, February 04, 2005 5:10 PM To: focus-ms@securityfocus.com Subject: active directory password policy Does anyone have any experience with remote users who do not login to the domain on a regular basis or at all, and have a password
expiration
policy in effect? We can't seem to come up with a good plan to handle these users. They only occassionally access domain resources such as webmail via the Internet or an internal website to do timesheets via vpn, and will not have the luxury of logging on to a machine connected to our LAN and getting the warning about soon to expire passwords. If our policy dictates passwords expire every 90 days, how can we avoid
the
inevitable calls regarding password resets? thx /William Stegman - Network Administrator/// TransCore - Hummelstownd
------------------------------------------------------------------------ --- ------------------------------------------------------------------------ --- ------------------------------------------------------------------------ --- ------------------------------------------------------------------------ --- Email contains Privileged & Confidential Information intended only for the recipient named. Dissemination or copying of email is strictly prohibited. If you have received this in error, notify St. Clair Hospital & return or destroy original. Information in this email is confidential & protected by state & federal law. Further disclosure is strictly prohibited. --------------------------------------------------------------------------- ---------------------------------------------------------------------------
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: Password Protected Screen Saver and Administrative Password, Tyson Leslie |
|---|---|
| Next by Date: | RE: Password Protected Screen Saver and Administrative Password, Beauford, Jason |
| Previous by Thread: | RE: active directory password policy, James Eaton-Lee |
| Next by Thread: | RE: active directory password policy, Sullivan Tim P |
| Indexes: | [Date] [Thread] [Top] [All Lists] |