RobD Posted March 3, 2015 Posted March 3, 2015 Hi All, I'm fairly new to a School and I've recently discovered a they dont have a password policy, so essentially staff can have a 4 letter password forever without the need to change it etc etc etc. I've created a change control and pushed it through SMT but there's been uproar from some staff who stay teachers so say its "unworkable" for teaching staff who dont have phones to call IT with etc. Which leads me onto my question, what policies are at your School and how do you get on? My proposal was: A) Set a password that has a minimum length of 8 characters. B) Change their password every 42 days. C) Meet certain password complexity requirements – a password will need to contain three of the following four categories in order to be valid. D) Use at least 24 unique passwords – 24 unique new passwords must be used before an old password can be reused. E) Lock-out period after 3 consecutive uses of the wrong password – if a user enters a password incorrectly 3 times, the account will be locked out for 15 minutes. Thanks
halbaradkenafin Posted March 3, 2015 Posted March 3, 2015 We've got two policies in place, one for staff who want to use our RDS system and one for everyone else. The general policy is: *At least 6 characters *At least one upper case, one lower case and one number *Lockout after 3 failed attempts *Currently no expiry but we may change that in the next few months to 60 days or something *Can't contain the users name Our Remote Access policy is a lot more convoluted and has things like not being able to use 3 consecutive characters in different passwords. We've also got an alternate method which uses pass phrases, which require at least 15 characters, at least 2 spaces and at least one upper case letter. Most staff choose the pass phrase option as it's less complicated than all the complex rules we've got in place for the password option.
unixman_again Posted March 3, 2015 Posted March 3, 2015 IMO D is a really bad idea. I've worked in places where this had been implemented and leads to hostility amongst users, who will make your life hell, unless you allow for example Password1, followed by Password2, Password3, etc. Also, 42 days is probably too soon. We have ours set to 100 days. Our policy is : 8 chars or more can't contain your name or user id at least one character from 3 of the 4 categories - upper case, lower case, number, symbol 3 unique passwords 100 days expiry lockout after 3 tries
tmcd35 Posted March 3, 2015 Posted March 3, 2015 Off the top of my head we have... * 8 characters - Google requirement * Change every 90 days, one a term * 3 unique passwords * lock out for 5 min after 5 attempts
Roberto Posted March 3, 2015 Posted March 3, 2015 Hi All, I'm fairly new to a School and I've recently discovered a they dont have a password policy, so essentially staff can have a 4 letter password forever without the need to change it etc etc etc. This is absolutely appalling - Staff need to appreciate that they have access to sensitive information about both the organisation and, more importantly, all kinds of personal information about students, some of which may well be vulnerable. I've created a change control and pushed it through SMT but there's been uproar from some staff who stay teachers so say its "unworkable" for teaching staff who dont have phones to call IT with etc. Which leads me onto my question, what policies are at your School and how do you get on? I'm not sure why "don't have phones to call IT with" is relevant? It's perfectly 'workable' to have a password policy - we enforce a minimum of six letters, a change time of 120 days, and a 10 password history. A) Set a password that has a minimum length of 8 characters. B) Change their password every 42 days. C) Meet certain password complexity requirements – a password will need to contain three of the following four categories in order to be valid. D) Use at least 24 unique passwords – 24 unique new passwords must be used before an old password can be reused. E) Lock-out period after 3 consecutive uses of the wrong password – if a user enters a password incorrectly 3 times, the account will be locked out for 15 minutes. Ok, some of these I would regard as a little stringent for some of the more computer-phobic people out there. What is the precise business requirement that is being served by using these choices instead of the ones I said are used at my place? (Not that I'm saying "I'm right and you're wrong" - our settings are the result of compromises between what I'd like to do and what staff can reliably handle, and I'm wondering if you've turned on all the features because you can, and a slight softening of your approach may take most of the sting out of the criticisms of your staff).
localzuk Posted March 3, 2015 Posted March 3, 2015 (edited) Ours is below. We had some teething problems when it was introduced, but we don't have much of a problem now. We have a few members of staff who find it impossible to remember passwords but that's about it. Our rules are based on what was advised to me by audit at my last school. [h=2]Staff password policy[/h]Password complexity is enabled, meaning: · Passwords must be at least 8 characters long · Must contain at least 1 uppercase letter · Must contain at least 1 lowercase letter · Must contain at least 1 numerical digit · Cannot be any of the last 24 passwords used · Cannot contain any part of the user’s name or username · Passwords must change every 45 days · Accounts become locked out after 10 invalid logon attempts, automatically resetting 60 minutes after latest failed attempt · Passwords are not stored in a “reversible” format, so cannot be recovered, only reset [h=2]Pupil password policy[/h]Password complexity is enabled, meaning: · Passwords must be at least 4 characters long · Accounts become locked out after 10 invalid logon attempt, automatically resetting 30 minutes after latest failed attempt · Passwords are not stored in a “reversible” format, so cannot be recovered, only reset Edited March 3, 2015 by localzuk
clockend25 Posted March 3, 2015 Posted March 3, 2015 For staff: Minimum Length: 6 Passwords remembered: 5 Must meet complexity requirements: Yes Minimum Password Age: 3 Maximum Password Age: 90 Failed Logon Attemps Allowed: 5 Pretty standard.
pcstru Posted March 3, 2015 Posted March 3, 2015 My proposal was: We have much the same as AD policy, but I'm happy to run them a lot longer than 42 days in exchange for more entropy. We also have some policy in the AUP, such as not sharing passwords or allowing students access to accounts used by teachers. We still get the occasional gaff - teachers sending their laptops to us in the care of a student with the password written on a post it and stuck to the screen.
RobD Posted March 3, 2015 Author Posted March 3, 2015 Thanks for all the replies, its really appreciated. I think I'll look to extend the password change to possibly 80-90 days for try and fit better with terms. Its good to know we are unusual not having a policy as this should help my argument.
witch Posted March 4, 2015 Posted March 4, 2015 Ours is: 8 characters At least one capital letter At least one number Cannot use last 3 passwords (I fought this but this was the best I could get) Change once a term
Sagima Posted March 4, 2015 Posted March 4, 2015 ICT Staff - 11 characters, complex, yearly expiry Senior school and staff is 11 characters, complex, no expiration. Primary - 8 characters, simple (on promotion to senior school password is set to expire so they choose a new one) Infants - none (restricted logon to that part of the school)
howartp Posted April 27, 2015 Posted April 27, 2015 Just had an IT Security Audit last month. Our staff policy was: 6 Characters Complex (3 from 4) No re-use in 12 30 attempts before lockout 30 minute lockout period 1 Day minimum age Expires every 30 days Yes, staff moaned about the complexity initially, but they're essentially fine about it now. The auditor suggested we reduce the lockout threshold down to 5 - ie 5 failed attempts will lock the account. Otherwise a hacker (or bot) can try one a minute every minute forever. We did this, but we're getting calls about lockouts at least once per hour. Now we don't believe this is users failing their passwords, so we're now looking into what is causing it - many of them use iPads, but it's happening too often to be staff that have changed their AD password but not updated their mail client, for example. Temporarily raised it back to 10 attempts whilst I investigate. (Just before going to Governors tonight to present the results of the IT Audit which did say 'we have met this objective by....' but is now a bag of lies!)
smithson83 Posted April 27, 2015 Posted April 27, 2015 ...getting calls about lockouts at least once per hour. Now we don't believe this is users failing their passwords, so we're now looking into what is causing it ... We had that when we enforced our lockout and complexity policy, turn out to be a few teachers had joined their phones to the Wireless via RADIUS and forgot, phone was attempting to authenticate every few minutes, failing due to a password change and trying again when it woke up.
howartp Posted April 27, 2015 Posted April 27, 2015 We had that when we enforced our lockout and complexity policy, turn out to be a few teachers had joined their phones to the Wireless via RADIUS and forgot, phone was attempting to authenticate every few minutes, failing due to a password change and trying again when it woke up. Interesting... We tried Radius but turned it off cos it didn't work with our setup. However we do use other mechanisms which might possibly have same effect - I'll have a think.
Sagima Posted April 28, 2015 Posted April 28, 2015 We had that when we enforced our lockout and complexity policy, turn out to be a few teachers had joined their phones to the Wireless via RADIUS and forgot, phone was attempting to authenticate every few minutes, failing due to a password change and trying again when it woke up. Yes we suffered with that too
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now