Jump to content

Recommended Posts

Posted

I need to update our Domain Password Policy.

 

Just a few queries on changing this..

 

Do I set this in the default domain policy > Policies > Windows Settings > Security settings > Account Policies.

When I change this, will it force the password change immediately or upon next logon

 

What's everyone's settings for :

 

Maximum Password Age

Minimum Password Age

 

Thanks in advance.

Posted

Advice is to never require a password change - obviously if you upgrade the requirements you'll need to, but you shouldn't set a standard expiry period.

 

NCSC recommendations are: 

 

Never expire

No complexity

As long as possible - recommend multiple unrelated words as a passphrase

Posted (edited)
13 minutes ago, jmak said:

Never expire

No complexity

As long as possible - recommend multiple unrelated words as a passphrase

 

We're going with this, with a minimum length of twelve characters to comply with Cyber Essentials. Minimum password age needs to be at least 1 day else you can have users cycling through passwords to get back to what they had initially if you have "remember X number of previous passwords" set.

Edited by sideone
Posted

 

1 hour ago, maxrebo said:

Do I set this in the default domain policy > Policies > Windows Settings > Security settings > Account Policies.

When I change this, will it force the password change immediately or upon next logon

Not unless you're appeasing an auditor who's never heard of Password Setting Objects.  If you are, put something reasonable in there as a catchall and then put more granular policies in via PSOs (Active Directory Administrative Center > (domain name) > System > Password Settings Container.

 

If their password has expired, it'll force the change at next login.  If it hasn't expired, nothing will happen.

 

As others have said, you're strongly encouraged to enforce good passwords from the beginning using something like Entra ID Password Protection (https://aad.portal.azure.com/#blade/Microsoft_AAD_IAM/AuthenticationMethodsMenuBlade/PasswordProtection), require MFA and monitor for problems (365 Defender alerts, SpecOps Password Auditor, HiBP subscription (school discount available if you ask)) than force frequent password changes.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...