Jump to content

Article: Active Directory Password Security: A Guide for the UK Education Sector


Recommended Posts

Posted

Thanks for sharing this. We have been using this for years and it really does highlight the number of users who have breached or compromised passwords on your AD. The number of staff accounts that show up have dropped dramatically however the issue is students, students just don't get it. I feel with students it's very much a case of leading a horse to water and all that.

 

We run the ManageEngine ADSelfService Plus too which is configured to send out AD password reset notifications days before the user's AD password will expire. The email comprises of requirements that the user should have in their password.

 

It would be great for those who run cloud only user directories such as Azure AD and Google Workspace to have a report to say how many users have got breached / weak / known passwords as having accounts up in the cloud seems to be harder to audit.

  • Thanks 1
Posted
@timbo343 To see if Google Workspace thinks if a user has a weak password in Google admin Console you can go to Reporting>User Reports>Security. Here you can see which users have strong passwords and which have weak. You can also download this report.
  • Thanks 1
Posted
@timbo343 To see if Google Workspace thinks if a user has a weak password in Google admin Console you can go to Reporting>User Reports>Security. Here you can see which users have strong passwords and which have weak. You can also download this report.

 

Cheers @fiza, shame do you know if Google classes "weak passwords" as known breached passwords too?

Posted

Something else to consider - Azure AD password protection can be extended to on-premise AD if the users have at least a P1 licence. https://learn.microsoft.com/en-us/entra/identity/authentication/howto-password-ban-bad-on-premises-deploy

 

This'll use the same logic to block exposed or weak passwords that Azure uses, with the ability to add blocked terms (org name, etc) to the list.

 

I've deployed it before, it's pretty easy to get going

Posted

Hi Everyone,

 

Darren from Specops here. Great to see this has sparked a conversation. If you have any further questions about Specops Password Auditor (or any of our solutions for that matter!), feel free to ask in the comments or PM me. Remember SPA doesn't tell us any of your results and doesn't crack anyones password. We also update the free database every 2-3 months based on the latest breaches, telemetry from our daily updated online "Complete" database, our global honeypot network and other threat intelligence sources.

 

Cheers

 

Darren

Posted
Something else to consider - Azure AD password protection can be extended to on-premise AD if the users have at least a P1 licence. https://learn.microsoft.com/en-us/entra/identity/authentication/howto-password-ban-bad-on-premises-deploy

 

This'll use the same logic to block exposed or weak passwords that Azure uses, with the ability to add blocked terms (org name, etc) to the list.

 

I've deployed it before, it's pretty easy to get going

It's a certainly is a start if you already have those licenses. We have an interesting comparison between AADPP and Specops Password Policy and Breached Password Protection here

 

https://specopssoft.com/our-resources/azure-ad-password-protection-competitor/

 

Good ol' Microsoft always leaves room for improvements ;)

  • 1 month later...
Posted
Just trying to understand the output for breached passwords, I had a new user created today about 2 hours ago yet they are showing on the breached password list what is it exactly checking to say that their password is breached, especially as they only started 2 hours ago?
Posted
Just trying to understand the output for breached passwords, I had a new user created today about 2 hours ago yet they are showing on the breached password list what is it exactly checking to say that their password is breached, especially as they only started 2 hours ago?

 

Hi Disease, Thanks for downloading SPA and this question!

 

Basically the password that they changed to has been previously seen on our breached database. Depending on what password policy you are applying, it can be every easy for someone to set a breached password. The MS default policy rules are pretty terrible, even with complexity switched on it still only means 3 out of the 5 different character types (upper, lower, digits, special and unicode), and mustn't contain your name (first, last, samaccountmane and displayname)

 

So things like Password1234 would be a perfectly acceptable 12 character, "complex" MS password, but of course we all know it isn't. and Password12345 would be fine when that one expired

 

Typically we see that if you are still running the MS rules you'll be doing really well if you have less than 25% of your users running a breached password - and remember the list you have downloaded is a small list.

 

Hope that explains it and if you'd like to know how to block these words in the first place, and moving to a better policy (other than just asking them to change it) then feel free to ask and i can take you through some options.

 

Cheers

 

Darren

Posted
Thanks for answering the question for me Darren, I think by my calcs we are running at 23% using a breached password. I see that you do a trail of the Specops Password Policy, I may have a look at that.
Posted
Thanks for answering the question for me Darren, I think by my calcs we are running at 23% using a breached password. I see that you do a trail of the Specops Password Policy, I may have a look at that.

 

no worries at all! Don't forget we offer a free POC service, so we'll do a remote session and help you get it all setup, only takes a couple of hours and you are fully supported for the length of the trial. Because it's group policy based you can lock it down to a single user and single machine while you are testing, there's no schema updates involved, so perfectly safe to install even in a live environment.

Posted
What is the cost of Specops Password Policy to cover 1500 students and 175 staff?

 

Hi Fiza,

 

We don't like to put our pricing on public platforms, but we would be happy to speak to you about your requirements (there are options), generate you a tailored quote and demo (if you want to take a closer look at the capabilities and/or have questions). If you want to PM me your email address or i can pm you mine? Failing that you can always request a quote through our website

 

https://specopssoft.com/pricing-request/

 

Don't forget to mention you are a school as we'll provide special pricing for the education sector.

 

Cheers

 

Darren

  • 2 weeks later...
Posted

I've been a very happy user of Specops Password Policy for many years - and now have it installed across 40 schools (for staff only, not students).

I'd be happy to have PM conversations with any EG users about how I have implemented it if anyone is interested.

Posted
I've been a very happy user of Specops Password Policy for many years - and now have it installed across 40 schools (for staff only, not students).

I'd be happy to have PM conversations with any EG users about how I have implemented it if anyone is interested.

 

That's amazing to hear! Why only the staff? I had a few schools actually use Specops Password policy to "teach" students what a good password/passphrase is. So a relatively short (but unbreached) one in Year 7, and then increasing in length as they progress through each year up to full on 20+ character passphrases in Year 11.

 

 

By the way all, the latest version of Specops Password Policy dropped at the end of last week. This release focuses on improvements to the reporting functionality you can find the release notes here

 

https://specopssoft.com/support/en/password-policy/release-notes.htm

  • 7 months later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...