Door deze site te gebruiken, u gaat akkoord met de Privacybeleid.
Accepteren
EnterinITEnterinITEnterinIT
  • THUIS
  • IT-PRO
  • TECH
  • MICROSOFT
    • Azuur
    • ConfigMgr/SCCM
    • DPM
    • Orchestrator
    • Hyper-V
    • Microsoft Edge Insider
    • MSI
    • Kantoor 365
    • Kantoor insider
    • PowerBI
    • Skypen
    • SQL-server
    • Teams
  • VENSTERS
    • Windows-beheercentrum
    • Windows-client
    • Windows-server
  • SCCM-queryverzamelingslijst
Lezing: Ultimate Guide to Configuring Default Password Policy in Active Directory – Best Practices and Tips
Lettergrootte wijzigenAa
EnterinITEnterinIT
Lettergrootte wijzigenAa
  • THUIS
  • IT-PRO
  • TECH
  • MICROSOFT
  • VENSTERS
  • SCCM-queryverzamelingslijst
Zoekopdracht
  • THUIS
  • IT-PRO
  • TECH
  • MICROSOFT
    • Azuur
    • ConfigMgr/SCCM
    • DPM
    • Orchestrator
    • Hyper-V
    • Microsoft Edge Insider
    • MSI
    • Kantoor 365
    • Kantoor insider
    • PowerBI
    • Skypen
    • SQL-server
    • Teams
  • VENSTERS
    • Windows-beheercentrum
    • Windows-client
    • Windows-server
  • SCCM-queryverzamelingslijst
Het pro

Ultimate Guide to Configuring Default Password Policy in Active Directory – Best Practices and Tips

Gepubliceerd november 29, 2024
5 Min. gelezen
DEEL

Ultimate Guide to Configuring Default Password Policy in Active Directory – Best Practices and Tips. Standaard, Active Directory is configured with a default domain password policy. This policy defines the password requirements for Active Directory user accounts such as password length, age, and so on.

Inhoud
Password Policy SettingsEnforce password history:Maximum password age: Minimum password ageMinimum password lengthPassword must meet complexity requirementsStore passwords using reversible encryptionModify Default Domain Password Policy

Password Policy Settings

Enforce password history:

This setting defines how many unique passwords must be used before an old password can be reused. Bijvoorbeeld, if my current password is “Th334goore0!” then I can’t reuse that password until I’ve changed my password 24 times (or whatever number the policy is set to). This setting is useful so users don’t keep reusing the same password. The default setting is 24

Maximum password age:

This setting defines how long in days a password can be used before it needs to be changed. The default setting is 42 dagen

Minimum password age

This setting determines how long a password must be used before it can be changed. The default setting is 1 day

Minimum password length

This setting determines how many characters a password must have. The default is 7. This means my password must contain at least 7 characters.

Password must meet complexity requirements

If enabled passwords must meet these requirements:

  • Not contain the user’s account name or parts of the user’s full name that exceed two consecutive characters
  • Be at least six characters in length
  • Contain characters from three of the following four categories:
    • English uppercase characters (A through Z)
    • English lowercase characters (a through z)
    • Base 10 digits (0 through 9)
    • Non-alphabetic characters (for example, !, $, #, %)

This is enabled by default

Store passwords using reversible encryption

This setting determines if the operating system stores password using reversible encryption. This is essentially the same as storing the plantest versions of passwords. This policy should NEVER be set to enabled unless you have some very specific application requirements.

Modify Default Domain Password Policy

1. Log in to your Domain Controller (or use a windows client with installed RSAT). Klik op de Begin button and find in the apps list Windows Administrative Tools;

2. Klikken op Beheer van groepsbeleid;

3. Find Default Domain Policy (Forest\Domains\<Domain Name>\Group Policy Objects);

If you need to modify some of the settings contained in the Default Domain Policy GPO, it is recommended that you create a new GPO for this purpose, link it to the domain, and set the Enforce optie.

TechNet: Linking GPOs

Do not modify the default domain policy or default domain controller policy unless necessary. In plaats van, create a new GPO at the domain level and set it to override the default settings in the default policies.

TechNet: Establishing Group Policy Operational Guidelines

4. Rechtermuisknop klik op Default Domain Policy and select Edit;

5. Gaan naar Password Policy (Computer Configuration\Policies\Windows Settings\Security Settings\Password Policy) and configured the password policies settings to the configuration you desire;

6. Enforce password history – how many passwords the system will remember. How many unique passwords user must use when every time reset the password;

7. Maximum Password Age – how long will the password lives After this period user, will be prompted to reset the password. (You may set “0” for “unlimited” age time);

8. Minimum Password Age – the user may change the password after this period. (You may set “0” for “unlimited” age time);

9. Minimum Password Length – how long will be your passwords, but not less than this value;

10. Password must meet complexity requirements – you may set this parameter if you need in very strong passwords (small “a” and big “A” letters, digits “1” and special symbols “!');

11. Store passwords using reversible encryption – by default not used in the domain, only if the application required it.

You can also view the default password policy with Windows Powershell:

Get-ADDefaultDomainPasswordPolicy
PowerShell

TIP: Make sure you inform all your users when you are going to do this as it may trigger them to change their password the next time they log on.

OPMERKING: Even if you apply the password policies to the “Domain Controllers” OU it will not modify the domain’s password policy. As far as I know, this is the only exception to the rule as to how GPOs apply to objects.

GETAGD:Active DirectoryGroepsbeleidMicrosoft Windows-serverPowerShellRamen
Vorig artikel How to Install Windows 10 on Hyper-V Virtual Machine: Stapsgewijze gids
Volgend artikel Guide to Installing SCCM Requirements: SQL Configuration, Active Directory Schema Extending and Windows Server Roles Installation
Laat een reactie achter Laat een reactie achter

Laat een reactie achter Antwoord annuleren

Uw e-mailadres wordt niet gepubliceerd. Verplichte velden zijn gemarkeerd *

Deze site gebruikt Akismet om spam te verminderen. Ontdek hoe uw reactiegegevens worden verwerkt.

Vertaling

English中文(简体)DanskNederlandsFrançaisDeutschItaliano한국어PolskiPortuguêsRomânăEspañolУкраїнська
 Vertaling bewerken
door Transposh - Vertaalplugin voor Wordpress

Populaire berichten

Systeemvereisten voor Windows Server 2016
Windows-server
Configuration Manager Queryverzamelingslijst
Configuration Manager Queryverzamelingslijst
ConfiguratieMgr
Gestructureerde/beheerde navigatie ingeschakeld op moderne pagina's in klassieke teamsites
Technologie
SCCM Kan DP-locaties niet ophalen als de verwachte versie van MP
ConfiguratieMgr

Recente berichten

Fail2ban installeren en configureren voor SSH-bescherming op Ubuntu 24.04
Linux
FirewallD inschakelen en configureren op AlmaLinux
Linux
Gebruikers aanmaken en SSH-sleutel instellen in AlmaLinux
Linux
Hoe het wachtwoord op AlmaLinux opnieuw in te stellen
Linux

© 2023 EnterinIT

Ga naar mobiele versie
advertentiebanner
Welkom terug!

Log in op uw account

Gebruikersnaam of e-mailadres
Wachtwoord

Wachtwoord vergeten?