Jump to content

CTRL+ALT+DEL Allows changing any password. Any way to disable?


Recommended Posts

Posted

If a child presses CTRL, ALT, DELETE when logged in they get the options Lock this computer, Switch user, Log off and Change a password...

 

The issue is, the Change a password... option allows them to change any password. It autofills the username box with DOMAIN\Username but you can modify that to somebody else's.

 

Yes, this isn't a huge security issue as they could simply logon to that users account after shoulder-surfing their password, but we'd still like to remove it if we can. Unfortunately, the Googz is giving me people asking how to stop a user changing their own password.

  • Thanks 1
Posted

Err seems a weird idea :p But if you really want, there should still be the option under Administrative Temps -> System -> ctrl-alt-del options -> remote change password? Assuming it's still working from XP days anyway

 

Edit - Ninja'd but fixing spelling anyway :p

 

Steve

Posted

This group policy setting will remove the option on the CTRL, ALT, DELETE screen to change password:

 

User Configuration\Administrative Templates\System\Ctrl+Alt+Del Options\Remove Change Password

 

 

Capture.PNG

Posted (edited)
im sure there is an option in GPO for controlling what is on the CTRL ALT DELETE menu

perhaps user config admin templates system rings a bell

 

The only policies I can find are in User Configuration, Policies, Administrative Templates, System, Ctrl+Alt+Del Options (which we already use to get rid of the Task Manager link). The only remotely relevant option there is Remove Change Password. We'd still like to keep the ability to change their own passwords.

 

It also asks for the old password too so are users using generic ones?

No. Like I said, it's not a huge issue, as they still need to know the users password, but we'd still like to remove the opportunity anyway. The more barriers to user account vandalism, the better,

Edited by Garacesh
Posted
The only policies I can find are in User Configuration, Policies, Administrative Templates, System, Ctrl+Alt+Del Options. The only remotely relevant option there is Remove Change Password. We'd still like to keep the ability to change their own passwords.

 

You're not going to be able to have it both ways - there's no granularity to the change password dialog, its either on or off.

Posted

Not really sure what you're asking for then. If they know the password and login of someone else they can always change it. Or do you simply mean you don't want them to do it from their login and they'd need to login as the other user? Like "fixing" the username box on the reset option?

 

Steve

Posted
Not really sure what you're asking for then. If they know the password and login of someone else they can always change it. Or do you simply mean you don't want them to do it from their login and they'd need to login as the other user? Like "fixing" the username box on the reset option?

 

Steve

 

Basically, yes. Like I say, the more barriers there are, the better. Anybody can reset a password from any user is bad. If the user needs to actually log on first, it can be traced back to a machine (to which in theory a teacher can look at their seating plan and say "Yeah, Joe Bloggs uses that machine.").

Posted

So do they need to be able to change their own passwords at any time? or only when it expires etc? As removing that option still allows them to change it if it's running out as you get the popup box etc

 

Steve

Posted

Passwords don't expire, but it would help if they could change their own password and nobody else's (i.e. The only password that can be changes is the password of the current active session)

Kids shoulder-surf passwords a fair bit here. At best we get user areas full of HAHAHAHAHA UR GAY HACKED M8 and New Folder's 1-through-1,000,000. At worst it's missing coursework lots of file restoration. Just seems prudent to put up any barriers possible.

 

Still, if it can't be done, it can't be done.

Posted

But the hahaha wise they need to login :p Thus the confusion I guess. Can't do that without logging in the first place, and then the changing the password option is mute.

 

Really though it sounds like you're talking about a custom software/script to do it which forces the name as the logged on user :s Then just remove the CAD option, and their normal resets are via the custom route? Or did you want to stick with "normal" ways

 

Steve

Posted
If a child presses CTRL, ALT, DELETE when logged in they get the options Lock this computer, Switch user, Log off and Change a password...

 

The issue is, the Change a password... option allows them to change any password. It autofills the username box with DOMAIN\Username but you can modify that to somebody else's.

 

Yes, this isn't a huge security issue as they could simply logon to that users account after shoulder-surfing their password, but we'd still like to remove it if we can. Unfortunately, the Googz is giving me people asking how to stop a user changing their own password.

 

Don't they need to know the original password to change the password, therefore changing someone elses password would only work if they knew that password. Aware students share passwords sometimes though :-(

 

In GPO System/Ctrl+Alt=Del options there is ability to remove Lock, Task Manager and Change Password.

Posted
But the hahaha wise they need to login :p Thus the confusion I guess. Can't do that without logging in the first place, and then the changing the password option is mute.

Yeah, I was using it as a demonstration of user account vandalism :p

 

Really though it sounds like you're talking about a custom software/script to do it which forces the name as the logged on user :s Then just remove the CAD option, and their normal resets are via the custom route? Or did you want to stick with "normal" ways

 

Steve

Yeah. Kids aren't allowed to run scripts (SRP) so that wouldn't work.

 

Don't they need to know the original password to change the password, therefore changing someone elses password would only work if they knew that password. Aware students share passwords sometimes though :-(

Yeah, they do, so it's not a massive issue. If we (somehow) disable changing other users' passwords they can still just log in to that account and change it that way.

 

It's not like it's a glaring security hole or anything, just something we'd prefer to disable if we have the choice. But it looks like we don't. ¯\_(ツ)_/¯ C'est la vie.

Posted

You can only change another users password if you know their old one.

 

I think its good practice allowing users to pick their own rather than forcing one upon them. Prepares them for corporate life of changing every 30 days and keeps your network secure.

Posted (edited)
You can only change another users password if you know their old one.

 

I think its good practice allowing users to pick their own rather than forcing one upon them. Prepares them for corporate life of changing every 30 days and keeps your network secure.

 

At the first school I worked we ended up forcing the students to use a unique password that the teacher could work out. It saved 25+ visits from students a day. Teachers there did originally have the ability to change passwords but couldn't be bothered.

 

Strange thing was that the next school above year 5 had their own passwords and could remember them.

Edited by Davit2005

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...