Jump to content

Recommended Posts

Posted

Hi,

 

Spent this morning investigating printing issues, thought was a bad doc/ driver problem

but now looks like it is a password ageing issue:

 

I recently rolled out a fine grained password policy forcing some users to change their password

after 30 days,

 

What seems to be happening is some users are not being prompted to change their password when they 

login in the morning, then presumably the password "expires" during the day and then stuff breaks

like printing (jobs stuck at spooling to shared printer as presumably auth broken). A PC restart prompts

for a password change and all ok again.

 

Does that sound possible and what have I done wrong / how to fix ?

Posted

The password advice these days is not to change passwords (so it is not written on a post-it and stuck to the screen). Just use password complexity rules so it is a strong long password. (I set a minimum of 15 characters).

After a compromise (password was typed in the username field, on a projected teacher’s computer), I gave a new temporary password, and used A/D forced a password change.

  • Like 1
Posted

In Computer Configuration, Policies, Windows settings, Local Policies, Security Options you should see 'Interactive Logon: Prompt user to change password before expiration' and you give it a number of days and will remind people each time they login starting x number of days before the expiration.

  • Thanks 1
Posted

Nscs guidance is to not enforce password changes unless you have reason to suspect a password compromise and that you shouldn't enforce complexity rules (it is shown to reduce the security of passwords. 

If you use a password manager (encouraged) you can let the machine generate and save a highly complex password, but if it's a password that someone might need to remember, you're better off sticking to words: 

 

https://www.ncsc.gov.uk/collection/top-tips-for-staying-secure-online/three-random-words

 

After part of our organisation had an incident which we believe was down to a brute force attack, we set the minimum length of 16 characters. I use a password manager and unless it's restricted by the system, I use 30 character passwords.

  • Like 1
  • Thanks 1
Posted
13 hours ago, jmak said:

Nscs guidance is to not enforce password changes

yes this wasn't my decision, we had an audit and they told us to do it. Perhaps I should have quoted NSCS to them ?!

Posted (edited)

Don't know if it's changed recently, but Ping Castle used to have a section with a warning about all the users whose passwords were set to 'never expire'... I ignored it, but I think some sectors still enforce it.

I know LGfL make me change mine every x days, it also stops me reusing any previous password and lots of other limitations that always make it a ball-ache..

 

EDIT: Just worked out I have had to conjure up well over 30 completely unique passwords since we started with LGfL...

Edited by Koldov
Posted

It's been proven that having passwords forcibly change too often actually creates a higher risk of security issues as people end up just adding a digit onto their existing password or writing them down on post it notes etc as mentioned above.

 

Might want to reconsider changing the 30 day to 60 or 90 to be honest.

Posted (edited)

most staff here have a diary where they write down all their passwords, funny auditors didn't mention that.

edit just checked for most staff its 90 days(not 30)

edit: and pupil chromebooks (1 to 1 devices) with stickers with several accounts / passwords on

Edited by mrstrong
  • Like 1
Posted

I've used variations of the same password system for as long as I've been using computers. I get around the complexity requirements by putting numbers and special characters between words. The only time I change mine (outside of nonsensical forced changes) is when they get compromised, which I check for regularly.

 

Our password policy at school is linked to the policies of other systems like Go4Schools, making it easier to tell younger children what the requirements are. I'd love to just set it to length>16 though.

 

Back on topic...

 

Password manager depends on use case. We are a Google school so promote the use of Google's password manager in Chrome, but others exist. We use Zoho Vault in IT Services to share passwords and it's a powerful system with plugins for most modern browsers.

 

The fix is exactly this is you are on a Windows exclusive platform:

17 hours ago, phil0569 said:

In Computer Configuration, Policies, Windows settings, Local Policies, Security Options you should see 'Interactive Logon: Prompt user to change password before expiration' and you give it a number of days and will remind people each time they login starting x number of days before the expiration.

  • Thanks 1
Posted (edited)

As for the OP... I found this:

 

https://community.spiceworks.com/t/users-not-prompted-to-change-expired-password/512836/4

 

From what I seen the password expiry will run from the last time they changed it, so if they change it at 11:00, it will expire at 11:00 in 30 (60, 90) days. I wondered if there was a way to reset it overnight, so they have to change it before they log-on...?

 

 However, someone also mentions 'cached credentials' and being able to log-on even though their password has expired.

 

Also keep in mind if they use cached credentials to login it wont prompt the password change.

If they are logging in before the network connects, say on a laptop that has just turned on, it will log them in even though their password is expired.

 

Furthermore, Windows 7 & Windows 10 allows users to login to the notebook even if their password expire as there is a cached password. It seems that of all the security policies, Microsoft have seem to forget the “force users to change expired password if they are in the Domain network”.

 

 

 

 

 

 

Edited by Koldov
  • Thanks 1
Posted
1 hour ago, mrstrong said:

yes this wasn't my decision, we had an audit and they told us to do it. Perhaps I should have quoted NSCS to them ?!

...or said "Thank you for your advice, but we won't be doing that.  Instead as per NCSC and NIST guidance we use MFA (list details) wherever available and have processes in places (list processes here) to detect unusual behaviour and account compromises.  Forcing frequent rotation in conjunction with long holidays leads to passwords being written down."

 

"Don't rotate passwords" isn't the advice.  The advice is "have MFA in place on systems, have methods to detect account compromise and unusual behaviour and respond promptly to those detections.  Done all that?  OK, now you get them to pick one good password that they don't have to change unless something iffy is detected."

 

'cos otherwise you've got hundreds of "Thisisthe14thtimeIchangedthis!" quality passwords from the "let's make them change passwords regularly" regime.

  • Like 3
Posted
18 minutes ago, pete said:

'cos otherwise you've got hundreds of "Thisisthe14thtimeIchangedthis!" quality passwords from the "let's make them change passwords regularly" regime.

 

Approved...

 

image.thumb.png.f1d20e3aa91ae1534c6db94311fddcc4.png

  • Like 1
  • Haha 1
Posted
10 minutes ago, Koldov said:

 

Approved...

 

image.thumb.png.f1d20e3aa91ae1534c6db94311fddcc4.png

 

The password checker doesn't have the context that Bob is enough of an idiot to complain about how often he has to change his password and then use that rant (or a variation thereof) as his password.

  • Haha 1
Posted (edited)

When I started (many years ago), apparently the 3rd party that previously supported the school used 'changeme' as the generic first time password given out to new users for them to change when they first signed in.

 

Quite a few years later I had to do some work on the P.E. teacher's laptop. I needed to see the issue they were having when they were logged in, but they were taking a lesson outside... so I just asked them for their password.

 

Guess what it was...

 

EDIT: Bearing in mind there was no prevent reuse or strong password enforcement...

Edited by Koldov
Posted
4 hours ago, mrstrong said:

which one do you recommend ?

I use BitWarden. I like it because it's open source and the free version gives the features I need. However, you do have to trust their cloud. 

If you want to self host, KeePass is good and popular and arguably more secure, but it's less convenient

  • Thanks 1
Posted
3 hours ago, Koldov said:

When I started (many years ago), apparently the 3rd party that previously supported the school used 'changeme' as the generic first time password given out to new users for them to change when they first signed in.

 

Quite a few years later I had to do some work on the P.E. teacher's laptop. I needed to see the issue they were having when they were logged in, but they were taking a lesson outside... so I just asked them for their password.

 

Guess what it was...

 

EDIT: Bearing in mind there was no prevent reuse or strong password enforcement...

 

We added football team names to Entra ID's custom password ban list.  And months and 4-digit years.

Posted

I've seen this happen a couple of times. Often, it's because the user has logged in before a connection to AD has been made, and so is using the cached credentials (like you'd use when taking a laptop off-site) rather than checking with AD, or the off chance that someone has figured out that if your password has expired, you can enable airplane mode to disconnect form AD and still log in with your old password.

 

Locking the PC and getting the user to unlock usually brings up the password expiry prompt.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...