Home > Windows Tips > Windows in the Enterprise > Use Microsoft password settings to enforce IT policy
Win IT Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

WINDOWS IN THE ENTERPRISE

Use Microsoft password settings to enforce IT policy


Gary Olsen, Contributor
11.13.2007
Rating: -3.50- (out of 5)


News on enterprise Windows platforms and applications
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


Developing a corporate security policy — whether it involves antivirus software, safe passwords or personal firewalls — means striking a balance between securing network resources and minimizing user inconvenience.

Part of designing a security policy in Windows is configuring the parameters associated with "account security."

Although systems administrators know the technical details, it is important for IT managers to know how they work so they can make the right decision when determining the configuration settings. Some decisions regarding security policies can compromise overall security because admins tend to favor the solution that solves the problem rather than the one that ensures system security.

These settings are defined in the security section of Group Policy and are referred to as "account policies." An important feature of the account policies is that they can be defined only at the domain level to be effective on domain accounts. That means you cannot define a password policy for individual organizational units. Everyone in the domain uses the same policy.

There is a way in Windows 2008 to apply it more granularly, however. Let's examine the settings of each of these policies, their effect on the overall security strategy and their recommended values.

Password policies define characteristics of a password:

  • Password complexity – This setting forces the user to use a combination of characters. There are four types of characters recognized for "complexity," including uppercase letters, lowercase letters, numbers and special

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    incident management (IcM)  (SearchWinIT.com)
    problem management  (SearchWinIT.com)
    Windows Server Update Services  (SearchWinIT.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary


    characters such as &, % and $. To meet the complexity requirement, a password must contain at least three of these features or the user will get an error stating it doesn't meet complexity requirements.


  • Default setting: Enabled
    Recommended setting: Enabled

  • Store password with reversible encryption – This is for applications that require clear text passwords. Not many of them exist out there anymore.

  • Default setting: No
    Recommended setting: No

    Keeping hackers out with account lockout

    When a wrong password is entered a certain number of times, the account is locked out and must be reset by the administrator. This foils hackers because even if they guess the password, the account won't work until it is reset and has a new password. It is intended as a secondary line of defense so that hackers can guess only a few combinations at a time.

    But account lockout policies can also be frustrating for users and administrators alike. There are a number of normal conditions that will artificially inflate the badPasswordCount value and cause an account to lock out a valid user. Microsoft's account lockout best practices white paper covers those conditions.

    For anyone who wants to use them, here are the guidelines:

    Gary Olsen is a systems software engineer for Hewlett-Packard in Global Solutions Engineering. He authored Windows 2000: Active Directory Design and Deployment and co-authored Windows Server 2003 on HP ProLiant Servers. Gary is a Microsoft MVP for Directory Services and formerly for Windows File Systems.


    Rate this Tip
    To rate tips, you must be a member of SearchWinIT.com.
    Register now to start rating these tips. Log in if you are already a member.




    DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



    Windows Technology Updates, Reviews and Solutions

    Laptop Discounts with free coupon codes, huge savings at Notebook Review

    HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersIT Downloads
    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    SEARCH 
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 1999 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts