Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Policy enforcement- Admin accounts |
|---|---|
| Date: | Mon, 17 Dec 2007 16:55:20 +0000 |
In an active directory environment (windows 2003), I want to ensure lockout for administrator accounts also, in order to protect against attempts to brute force account password. The flipside is, we might have a DoS situation but I can live with it. Is there a tool I can deploy to ensure that admin account also locks out after certain no. of attemps?sounds like you want to create to group policy objects. one a standard for the domain and one for the administrators. Personally I'd do this by putting the administrative users in an OU called admin for instance and creating a personalised GPO and apply it to that OU. Then create a standard one and apply that to the domain
Also, ONLY for admin accounts, I want to enforce certain settings like: Password should contain atleast 15 characters, should not contain a dictionary word etc.
My normal password policy for AD user accounts, set at the domain level is a minimum of 8 chars but I want to deploy this special policy of 15 chars minimum for admin accounts.
How should I go about this?
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/directory/activedirectory/stepbystep/strngpw.mspx
has more details.
hope that helps.
mgk
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: Policy enforcement- Admin accounts, Scalcione.David |
|---|---|
| Next by Date: | RE: Policy enforcement- Admin accounts, Ricky Kerby |
| Previous by Thread: | RE: Policy enforcement- Admin accounts, Scalcione.David |
| Next by Thread: | Discussing Microsoft Forefront security attempt, WALI |
| Indexes: | [Date] [Thread] [Top] [All Lists] |