Jump to content

Recommended Posts

Posted

Evening All,

 

Random question but is there any way to retrieve AD passwords? Not resetting etc. (Obviously got full access domain admin wise etc)

 

Just looking at moving forwards with some more cloud services (O365 already in place prior to my starting etc), and after digging around it seems there's no password policies in place really. Some teachers have had passwords for 6+ years (To quote them), others who joined at another time have to reset every 3 months, others every 1, so want to implement a site-wide policy here.

 

But obviously with the amount of external services/remote access/webpages/SIMs these accounts are used for I'll be advising SLT that moving forwards we need more complex passwords (6 char only restrictions so far) at least for staff members with all they can access.

 

Just would have liked to have some report to show how lacking (assumption) the current choices of passwords/complexity are (When teachers have complained before that they can't use 5 char password kind of says it all :p)

 

(Just to clarify obviously have full domain admin access over accounts/emails etc, and would be only with SLT agreement)

 

Thanks,

Steve

Posted (edited)

You can do a search on AD (top option but I can't think of the name of it at the minute) to find accounts that have 'Do Not Expire' on them. But if you're trying to find actual passwords then yeah; unless reversible encryption is enabled it's a no.

 

Though I find staff will often tell me if I ask them which always makes me laugh and tell them off.

 

Do you have Fine Grained Passwords enabled too? As otherwise Staff should all be hit by the one and only policy at the default domain GPO.

Edited by Killer_Bot
Posted

Best way is to simply export the hashes and run a password crack tool using either a dictionary based attack or rainbow tables to see what weak passwords are in use.

 

Ben

Posted
Decide a date, publish it to staff get SMT involved and on that date set some requirements and they will be forced to change their password. Not uncommon to have to change every 30 days but we had ours at 90. Ask them if they would share their bank PIN!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...