windowsman Posted November 29, 2014 Posted November 29, 2014 Good Evening, I am receiving quite a strange error in most of my user accounts on the server, upon creating a new account I just wanted to give a simple 5 digit passcode, but the server is having none of it and is wanting a 'complex' password? I am guessing that is a strong 8 character password, but I would like this removed. Is there any way? Kind Regards
elsiegee40 Posted November 29, 2014 Posted November 29, 2014 Why would you want to reduce password complexity? What level of authority do you have on the network?
windowsman Posted November 29, 2014 Author Posted November 29, 2014 I am the Administrator of the Server. I do not want 8 character passwords, I would like to choose how many characters are in the user's passwords.
elsiegee40 Posted November 29, 2014 Posted November 29, 2014 (edited) I am the Administrator of the Server. I do not want 8 character passwords, I would like to choose how many characters are in the user's passwords. Password complexity features are there for very serious reasons to do with Data Protection and security. Is this a test network or a live one? To be honest, this is fairly basic stuff for a network technician, so forgive me for feeling concerned that someone seems to want to be able to put a network at risk. This is the kind of thing to discuss with your network manager. Edited November 29, 2014 by elsiegee40
fairm010 Posted November 29, 2014 Posted November 29, 2014 I agree with Elsiegee40. We enforce at least 8 characters, numbers and symbols for both Staff and Students. We also set an account lockout after 3 attempts. Passwords are the weakest part of any network, don't weaken it further. 1
mrnoisy Posted November 29, 2014 Posted November 29, 2014 Jeez you guys are a bit serious about you passwords aren't you ? It's a school network not NASA :-) Our yr7's can't even remember their names yet alone passwords, most staff have theirs on a post it note !
fairm010 Posted November 29, 2014 Posted November 29, 2014 It's a school network yes but a staff login provides access to the behaviour tracking system, the room booking system, confidential SEN information in the staff shared areas or the teachers my docs. If they gain access to SIMS then goodness knows what could happen.
fairm010 Posted November 29, 2014 Posted November 29, 2014 If I knew my staff were writing their password on post its id be having words with SLT. Would you leave your PIN number on display?
elsiegee40 Posted November 30, 2014 Posted November 30, 2014 (edited) There is a huge amount of data on any school network that is subject to the Data Protection Act. Schools are not exempt. Any breach of DPA can be subject to massive fines, both corporate and individual, and anyone reducing password complexity needs to think very hard... especially if their network has any sort of connection to the outside world. Since Server 2008 it has been possible to have different complexity requirements for different groups of users which can be useful for the very youngest children in primary schools for example. By Year 7, there are few who cannot cope with capital letters and punctuation in a password and it's an eSafety lesson that, if they don't know already, they should be taught immediately @mrnoisy. Ordinarily, it would be a quick answer to this question, but the way the question is couched raises suspicions about the experience (and role) of OP. It seems s/he has little experience of network administration and, as there isn't any attempt to justify the wish to change, no knowledge of why reducing complexity is not such a good idea. That is the lesson that needs to be taught first. Edited November 30, 2014 by elsiegee40
windowsman Posted November 30, 2014 Author Posted November 30, 2014 I understand now about this issue, the passwords will remain at 8 or more characters. Apologies for any inconvenience.
Mr_Jiminy Posted November 30, 2014 Posted November 30, 2014 Jeez you guys are a bit serious about you passwords aren't you ? It's a school network not NASA :-) Our yr7's can't even remember their names yet alone passwords, most staff have theirs on a post it note ! Hahahaha spoken like someone who has never had a network audit.
mrnoisy Posted November 30, 2014 Posted November 30, 2014 Actually we have, there's more to Network security than password protection, but I won't presume you know nothing about this. 1
elsiegee40 Posted November 30, 2014 Posted November 30, 2014 (edited) Actually we have, there's more to Network security than password protection, but I won't presume you know nothing about this. Then maybe an acknowledgement that password protection has its part in network security would have been better than your original post in this thread. OP only asked about passwords, not about the rest. Taking password security seriously is just as important as the rest. Edited November 30, 2014 by elsiegee40
Mr_Jiminy Posted November 30, 2014 Posted November 30, 2014 Actually we have, there's more to Network security than password protection, but I won't presume you know nothing about this. Indeed there is, but this thread is about passwords.
Domino Posted December 1, 2014 Posted December 1, 2014 If I knew my staff were writing their password on post its id be having words with SLT. Would you leave your PIN number on display? is that the Personal Identification Number Number?
fairm010 Posted December 1, 2014 Posted December 1, 2014 How odd, I never thought of it like that! From this day forward it is a PI Number. - - - Updated - - - I should have just said: Would you leave your PIN on display?
mightyfox Posted December 1, 2014 Posted December 1, 2014 Hi Windowsman, Can i ask what the reason for reducing the complexity requirements was? As a windows server administrator you should surely know how easy this is to do with access to the server, therefore i wonder about your level of access?
Oaktech Posted December 1, 2014 Posted December 1, 2014 If you need a group that has a less complex password policy (say, year 4 and below?) Then I suggest you check out the respective MS articles on creating a 'fine grained password policy' I strongly recomend that any adult should have a complex password - you should probably, in your fine grain password policy, select the 'must comply with complexity requirements' to make sure they aren't creating a password of password or 12345678. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now