Dos_Box Posted December 20, 2023 Posted December 20, 2023 (edited) You can view the page at https://edugeek.me/article/727 Edited December 20, 2023 by ZeroHour 1
timbo343 Posted December 20, 2023 Posted December 20, 2023 Thanks for sharing this. We have been using this for years and it really does highlight the number of users who have breached or compromised passwords on your AD. The number of staff accounts that show up have dropped dramatically however the issue is students, students just don't get it. I feel with students it's very much a case of leading a horse to water and all that. We run the ManageEngine ADSelfService Plus too which is configured to send out AD password reset notifications days before the user's AD password will expire. The email comprises of requirements that the user should have in their password. It would be great for those who run cloud only user directories such as Azure AD and Google Workspace to have a report to say how many users have got breached / weak / known passwords as having accounts up in the cloud seems to be harder to audit. 1
fiza Posted December 20, 2023 Posted December 20, 2023 @timbo343 To see if Google Workspace thinks if a user has a weak password in Google admin Console you can go to Reporting>User Reports>Security. Here you can see which users have strong passwords and which have weak. You can also download this report. 1
timbo343 Posted December 20, 2023 Posted December 20, 2023 @timbo343 To see if Google Workspace thinks if a user has a weak password in Google admin Console you can go to Reporting>User Reports>Security. Here you can see which users have strong passwords and which have weak. You can also download this report. Cheers @fiza, shame do you know if Google classes "weak passwords" as known breached passwords too?
fiza Posted December 20, 2023 Posted December 20, 2023 Cheers @fiza, shame do you know if Google classes "weak passwords" as known breached passwords too? Sorry, I don't.
dmj Posted December 20, 2023 Posted December 20, 2023 Cheers @fiza, shame do you know if Google classes "weak passwords" as known breached passwords too? There's an automated alert on leaked passwords: https://support.google.com/a/answer/9104586?hl=en#zippy=
fiza Posted December 20, 2023 Posted December 20, 2023 There's an automated alert on leaked passwords: https://support.google.com/a/answer/9104586?hl=en#zippy= I'd forgotten about this section! Thanks for the reminder. The leaked passwords alert is system defined so is set to send an email to all super admins.
Domino Posted December 20, 2023 Posted December 20, 2023 Something else to consider - Azure AD password protection can be extended to on-premise AD if the users have at least a P1 licence. https://learn.microsoft.com/en-us/entra/identity/authentication/howto-password-ban-bad-on-premises-deploy This'll use the same logic to block exposed or weak passwords that Azure uses, with the ability to add blocked terms (org name, etc) to the list. I've deployed it before, it's pretty easy to get going
darrenjSpecops Posted December 20, 2023 Posted December 20, 2023 Hi Everyone, Darren from Specops here. Great to see this has sparked a conversation. If you have any further questions about Specops Password Auditor (or any of our solutions for that matter!), feel free to ask in the comments or PM me. Remember SPA doesn't tell us any of your results and doesn't crack anyones password. We also update the free database every 2-3 months based on the latest breaches, telemetry from our daily updated online "Complete" database, our global honeypot network and other threat intelligence sources. Cheers Darren
darrenjSpecops Posted December 20, 2023 Posted December 20, 2023 Something else to consider - Azure AD password protection can be extended to on-premise AD if the users have at least a P1 licence. https://learn.microsoft.com/en-us/entra/identity/authentication/howto-password-ban-bad-on-premises-deploy This'll use the same logic to block exposed or weak passwords that Azure uses, with the ability to add blocked terms (org name, etc) to the list. I've deployed it before, it's pretty easy to get going It's a certainly is a start if you already have those licenses. We have an interesting comparison between AADPP and Specops Password Policy and Breached Password Protection here https://specopssoft.com/our-resources/azure-ad-password-protection-competitor/ Good ol' Microsoft always leaves room for improvements
Disease Posted January 23, 2024 Posted January 23, 2024 Just trying to understand the output for breached passwords, I had a new user created today about 2 hours ago yet they are showing on the breached password list what is it exactly checking to say that their password is breached, especially as they only started 2 hours ago?
darrenjSpecops Posted January 23, 2024 Posted January 23, 2024 Just trying to understand the output for breached passwords, I had a new user created today about 2 hours ago yet they are showing on the breached password list what is it exactly checking to say that their password is breached, especially as they only started 2 hours ago? Hi Disease, Thanks for downloading SPA and this question! Basically the password that they changed to has been previously seen on our breached database. Depending on what password policy you are applying, it can be every easy for someone to set a breached password. The MS default policy rules are pretty terrible, even with complexity switched on it still only means 3 out of the 5 different character types (upper, lower, digits, special and unicode), and mustn't contain your name (first, last, samaccountmane and displayname) So things like Password1234 would be a perfectly acceptable 12 character, "complex" MS password, but of course we all know it isn't. and Password12345 would be fine when that one expired Typically we see that if you are still running the MS rules you'll be doing really well if you have less than 25% of your users running a breached password - and remember the list you have downloaded is a small list. Hope that explains it and if you'd like to know how to block these words in the first place, and moving to a better policy (other than just asking them to change it) then feel free to ask and i can take you through some options. Cheers Darren
Disease Posted January 23, 2024 Posted January 23, 2024 Thanks for answering the question for me Darren, I think by my calcs we are running at 23% using a breached password. I see that you do a trail of the Specops Password Policy, I may have a look at that.
darrenjSpecops Posted January 23, 2024 Posted January 23, 2024 Thanks for answering the question for me Darren, I think by my calcs we are running at 23% using a breached password. I see that you do a trail of the Specops Password Policy, I may have a look at that. no worries at all! Don't forget we offer a free POC service, so we'll do a remote session and help you get it all setup, only takes a couple of hours and you are fully supported for the length of the trial. Because it's group policy based you can lock it down to a single user and single machine while you are testing, there's no schema updates involved, so perfectly safe to install even in a live environment.
fiza Posted January 23, 2024 Posted January 23, 2024 What is the cost of Specops Password Policy to cover 1500 students and 175 staff?
darrenjSpecops Posted January 23, 2024 Posted January 23, 2024 What is the cost of Specops Password Policy to cover 1500 students and 175 staff? Hi Fiza, We don't like to put our pricing on public platforms, but we would be happy to speak to you about your requirements (there are options), generate you a tailored quote and demo (if you want to take a closer look at the capabilities and/or have questions). If you want to PM me your email address or i can pm you mine? Failing that you can always request a quote through our website https://specopssoft.com/pricing-request/ Don't forget to mention you are a school as we'll provide special pricing for the education sector. Cheers Darren
darrenjSpecops Posted January 23, 2024 Posted January 23, 2024 By The way - a new update to the Breached Password Database is being released today with a further 7+million passwords added from a our Threat Intelligence platform https://outpost24.com/products/cyber-threat-intelligence/ just run Specops Password Auditor again and it'll prompt you to download the new database.
kearton Posted February 7, 2024 Posted February 7, 2024 I've been a very happy user of Specops Password Policy for many years - and now have it installed across 40 schools (for staff only, not students). I'd be happy to have PM conversations with any EG users about how I have implemented it if anyone is interested.
darrenjSpecops Posted February 7, 2024 Posted February 7, 2024 I've been a very happy user of Specops Password Policy for many years - and now have it installed across 40 schools (for staff only, not students). I'd be happy to have PM conversations with any EG users about how I have implemented it if anyone is interested. That's amazing to hear! Why only the staff? I had a few schools actually use Specops Password policy to "teach" students what a good password/passphrase is. So a relatively short (but unbreached) one in Year 7, and then increasing in length as they progress through each year up to full on 20+ character passphrases in Year 11. By the way all, the latest version of Specops Password Policy dropped at the end of last week. This release focuses on improvements to the reporting functionality you can find the release notes here https://specopssoft.com/support/en/password-policy/release-notes.htm
kearton Posted September 30, 2024 Posted September 30, 2024 (edited) Why only the staff? #becausecost 7000 Staff we can afford. Tens of thousands of students we cannot Edited September 30, 2024 by kearton
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now