mrstrong Posted June 25, 2025 Posted June 25, 2025 Hi, Spent this morning investigating printing issues, thought was a bad doc/ driver problem but now looks like it is a password ageing issue: I recently rolled out a fine grained password policy forcing some users to change their password after 30 days, What seems to be happening is some users are not being prompted to change their password when they login in the morning, then presumably the password "expires" during the day and then stuff breaks like printing (jobs stuck at spooling to shared printer as presumably auth broken). A PC restart prompts for a password change and all ok again. Does that sound possible and what have I done wrong / how to fix ?
Julian Posted June 25, 2025 Posted June 25, 2025 The password advice these days is not to change passwords (so it is not written on a post-it and stuck to the screen). Just use password complexity rules so it is a strong long password. (I set a minimum of 15 characters). After a compromise (password was typed in the username field, on a projected teacher’s computer), I gave a new temporary password, and used A/D forced a password change. 1
phil0569 Posted June 25, 2025 Posted June 25, 2025 In Computer Configuration, Policies, Windows settings, Local Policies, Security Options you should see 'Interactive Logon: Prompt user to change password before expiration' and you give it a number of days and will remind people each time they login starting x number of days before the expiration. 1
jmak Posted June 25, 2025 Posted June 25, 2025 Nscs guidance is to not enforce password changes unless you have reason to suspect a password compromise and that you shouldn't enforce complexity rules (it is shown to reduce the security of passwords. If you use a password manager (encouraged) you can let the machine generate and save a highly complex password, but if it's a password that someone might need to remember, you're better off sticking to words: https://www.ncsc.gov.uk/collection/top-tips-for-staying-secure-online/three-random-words After part of our organisation had an incident which we believe was down to a brute force attack, we set the minimum length of 16 characters. I use a password manager and unless it's restricted by the system, I use 30 character passwords. 1 1
mrstrong Posted June 26, 2025 Author Posted June 26, 2025 13 hours ago, jmak said: Nscs guidance is to not enforce password changes yes this wasn't my decision, we had an audit and they told us to do it. Perhaps I should have quoted NSCS to them ?!
Olliedawg Posted June 26, 2025 Posted June 26, 2025 30 days is insane, get ready to see post it notes with passwords written on them Who did the audit?
Koldov Posted June 26, 2025 Posted June 26, 2025 (edited) Don't know if it's changed recently, but Ping Castle used to have a section with a warning about all the users whose passwords were set to 'never expire'... I ignored it, but I think some sectors still enforce it. I know LGfL make me change mine every x days, it also stops me reusing any previous password and lots of other limitations that always make it a ball-ache.. EDIT: Just worked out I have had to conjure up well over 30 completely unique passwords since we started with LGfL... Edited June 26, 2025 by Koldov
mrstrong Posted June 26, 2025 Author Posted June 26, 2025 13 hours ago, jmak said: I use a password manager which one do you recommend ?
PotNoodleTech Posted June 26, 2025 Posted June 26, 2025 It's been proven that having passwords forcibly change too often actually creates a higher risk of security issues as people end up just adding a digit onto their existing password or writing them down on post it notes etc as mentioned above. Might want to reconsider changing the 30 day to 60 or 90 to be honest.
mrstrong Posted June 26, 2025 Author Posted June 26, 2025 (edited) most staff here have a diary where they write down all their passwords, funny auditors didn't mention that. edit : just checked for most staff its 90 days(not 30) edit: and pupil chromebooks (1 to 1 devices) with stickers with several accounts / passwords on Edited June 26, 2025 by mrstrong 1
Sephiroth Posted June 26, 2025 Posted June 26, 2025 I've used variations of the same password system for as long as I've been using computers. I get around the complexity requirements by putting numbers and special characters between words. The only time I change mine (outside of nonsensical forced changes) is when they get compromised, which I check for regularly. Our password policy at school is linked to the policies of other systems like Go4Schools, making it easier to tell younger children what the requirements are. I'd love to just set it to length>16 though. Back on topic... Password manager depends on use case. We are a Google school so promote the use of Google's password manager in Chrome, but others exist. We use Zoho Vault in IT Services to share passwords and it's a powerful system with plugins for most modern browsers. The fix is exactly this is you are on a Windows exclusive platform: 17 hours ago, phil0569 said: In Computer Configuration, Policies, Windows settings, Local Policies, Security Options you should see 'Interactive Logon: Prompt user to change password before expiration' and you give it a number of days and will remind people each time they login starting x number of days before the expiration. 1
Koldov Posted June 26, 2025 Posted June 26, 2025 (edited) As for the OP... I found this: https://community.spiceworks.com/t/users-not-prompted-to-change-expired-password/512836/4 From what I seen the password expiry will run from the last time they changed it, so if they change it at 11:00, it will expire at 11:00 in 30 (60, 90) days. I wondered if there was a way to reset it overnight, so they have to change it before they log-on...? However, someone also mentions 'cached credentials' and being able to log-on even though their password has expired. Also keep in mind if they use cached credentials to login it wont prompt the password change. If they are logging in before the network connects, say on a laptop that has just turned on, it will log them in even though their password is expired. Furthermore, Windows 7 & Windows 10 allows users to login to the notebook even if their password expire as there is a cached password. It seems that of all the security policies, Microsoft have seem to forget the “force users to change expired password if they are in the Domain network”. Edited June 26, 2025 by Koldov 1
pete Posted June 26, 2025 Posted June 26, 2025 1 hour ago, mrstrong said: yes this wasn't my decision, we had an audit and they told us to do it. Perhaps I should have quoted NSCS to them ?! ...or said "Thank you for your advice, but we won't be doing that. Instead as per NCSC and NIST guidance we use MFA (list details) wherever available and have processes in places (list processes here) to detect unusual behaviour and account compromises. Forcing frequent rotation in conjunction with long holidays leads to passwords being written down." "Don't rotate passwords" isn't the advice. The advice is "have MFA in place on systems, have methods to detect account compromise and unusual behaviour and respond promptly to those detections. Done all that? OK, now you get them to pick one good password that they don't have to change unless something iffy is detected." 'cos otherwise you've got hundreds of "Thisisthe14thtimeIchangedthis!" quality passwords from the "let's make them change passwords regularly" regime. 3
Koldov Posted June 26, 2025 Posted June 26, 2025 18 minutes ago, pete said: 'cos otherwise you've got hundreds of "Thisisthe14thtimeIchangedthis!" quality passwords from the "let's make them change passwords regularly" regime. Approved... 1 1
pete Posted June 26, 2025 Posted June 26, 2025 10 minutes ago, Koldov said: Approved... The password checker doesn't have the context that Bob is enough of an idiot to complain about how often he has to change his password and then use that rant (or a variation thereof) as his password. 1
Koldov Posted June 26, 2025 Posted June 26, 2025 (edited) When I started (many years ago), apparently the 3rd party that previously supported the school used 'changeme' as the generic first time password given out to new users for them to change when they first signed in. Quite a few years later I had to do some work on the P.E. teacher's laptop. I needed to see the issue they were having when they were logged in, but they were taking a lesson outside... so I just asked them for their password. Guess what it was... EDIT: Bearing in mind there was no prevent reuse or strong password enforcement... Edited June 26, 2025 by Koldov
jmak Posted June 26, 2025 Posted June 26, 2025 4 hours ago, mrstrong said: which one do you recommend ? I use BitWarden. I like it because it's open source and the free version gives the features I need. However, you do have to trust their cloud. If you want to self host, KeePass is good and popular and arguably more secure, but it's less convenient 1
pete Posted June 26, 2025 Posted June 26, 2025 3 hours ago, Koldov said: When I started (many years ago), apparently the 3rd party that previously supported the school used 'changeme' as the generic first time password given out to new users for them to change when they first signed in. Quite a few years later I had to do some work on the P.E. teacher's laptop. I needed to see the issue they were having when they were logged in, but they were taking a lesson outside... so I just asked them for their password. Guess what it was... EDIT: Bearing in mind there was no prevent reuse or strong password enforcement... We added football team names to Entra ID's custom password ban list. And months and 4-digit years.
timbo343 Posted June 26, 2025 Posted June 26, 2025 Touching back on notifications for password resets, we have ManageEngine's Self Service Passwors which can be configured to send out password notification emails. We have it 20, 10, 5, 3, 2, 1 days. https://www.manageengine.com/products/self-service-password/free-password-expiry-notification-tool.html
itskdog Posted June 27, 2025 Posted June 27, 2025 I've seen this happen a couple of times. Often, it's because the user has logged in before a connection to AD has been made, and so is using the cached credentials (like you'd use when taking a laptop off-site) rather than checking with AD, or the off chance that someone has figured out that if your password has expired, you can enable airplane mode to disconnect form AD and still log in with your old password. Locking the PC and getting the user to unlock usually brings up the password expiry prompt.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now