Jump to content

darrenjSpecops

Members
  • Posts

    7
  • Joined

  • Last visited

Reputation

0 Neutral

About darrenjSpecops

  1. That's amazing to hear! Why only the staff? I had a few schools actually use Specops Password policy to "teach" students what a good password/passphrase is. So a relatively short (but unbreached) one in Year 7, and then increasing in length as they progress through each year up to full on 20+ character passphrases in Year 11. By the way all, the latest version of Specops Password Policy dropped at the end of last week. This release focuses on improvements to the reporting functionality you can find the release notes here https://specopssoft.com/support/en/password-policy/release-notes.htm
  2. By The way - a new update to the Breached Password Database is being released today with a further 7+million passwords added from a our Threat Intelligence platform https://outpost24.com/products/cyber-threat-intelligence/ just run Specops Password Auditor again and it'll prompt you to download the new database.
  3. Hi Fiza, We don't like to put our pricing on public platforms, but we would be happy to speak to you about your requirements (there are options), generate you a tailored quote and demo (if you want to take a closer look at the capabilities and/or have questions). If you want to PM me your email address or i can pm you mine? Failing that you can always request a quote through our website https://specopssoft.com/pricing-request/ Don't forget to mention you are a school as we'll provide special pricing for the education sector. Cheers Darren
  4. no worries at all! Don't forget we offer a free POC service, so we'll do a remote session and help you get it all setup, only takes a couple of hours and you are fully supported for the length of the trial. Because it's group policy based you can lock it down to a single user and single machine while you are testing, there's no schema updates involved, so perfectly safe to install even in a live environment.
  5. Hi Disease, Thanks for downloading SPA and this question! Basically the password that they changed to has been previously seen on our breached database. Depending on what password policy you are applying, it can be every easy for someone to set a breached password. The MS default policy rules are pretty terrible, even with complexity switched on it still only means 3 out of the 5 different character types (upper, lower, digits, special and unicode), and mustn't contain your name (first, last, samaccountmane and displayname) So things like Password1234 would be a perfectly acceptable 12 character, "complex" MS password, but of course we all know it isn't. and Password12345 would be fine when that one expired Typically we see that if you are still running the MS rules you'll be doing really well if you have less than 25% of your users running a breached password - and remember the list you have downloaded is a small list. Hope that explains it and if you'd like to know how to block these words in the first place, and moving to a better policy (other than just asking them to change it) then feel free to ask and i can take you through some options. Cheers Darren
  6. It's a certainly is a start if you already have those licenses. We have an interesting comparison between AADPP and Specops Password Policy and Breached Password Protection here https://specopssoft.com/our-resources/azure-ad-password-protection-competitor/ Good ol' Microsoft always leaves room for improvements
  7. Hi Everyone, Darren from Specops here. Great to see this has sparked a conversation. If you have any further questions about Specops Password Auditor (or any of our solutions for that matter!), feel free to ask in the comments or PM me. Remember SPA doesn't tell us any of your results and doesn't crack anyones password. We also update the free database every 2-3 months based on the latest breaches, telemetry from our daily updated online "Complete" database, our global honeypot network and other threat intelligence sources. Cheers Darren
×
×
  • Create New...