|
If you are up to writing a change notify function, why not
just write a pasword filter and look up the account and reject the change?
Actually if you follow good processes and have a second ID for the administrator
accounts you can pick some prefix character and any ID that comes through with
that prefix can be forced to 15 characters and you don't have to look anything
up.
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Bahta, Nathaniel V CTR USAF NASIC/SCNA Sent: Thursday, August 31, 2006 8:58 AM To: [email protected] Subject: RE: [ActiveDir] Seperate Administrator password policy I thought about that, but that does not prohibit you from
setting a password less than 15 characters. I thought about setting it up
to run on a changenotify event and then if the length was less than 15, disable
the account, but I think that is a bit harsh. I dont know of a way of
stopping the setting of a password less than 15 characters without a actual
subdomain. That PPE looks like it would do the trick, but I dont think we
are being given third party tools to implement this security
measure.
Nate From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Za Vue Sent: Thursday, August 31, 2006 8:39 AM To: [email protected] Subject: Re: [ActiveDir] Seperate Administrator password policy -Z.V. Almeida Pinto, Jorge de wrote:
|
- RE: [ActiveDir] Seperate Administra... Grillenmeier, Guido
- RE: [ActiveDir] Seperate Admin... Bahta, Nathaniel V CTR USAF NASIC/SCNA
- Re: [ActiveDir] Seperate A... Mark Parris
- RE: [ActiveDir] Seperate Admin... David Adner
- RE: [ActiveDir] Seperate Admin... Almeida Pinto, Jorge de
- RE: [ActiveDir] Seperate Admin... joe
- RE: [ActiveDir] Seperate Admin... Katrin Wilhelm
- RE: [ActiveDir] Seperate A... joe
- RE: [ActiveDir] Sepera... Bahta, Nathaniel V CTR USAF NASIC/SCNA
- [ActiveDir] DNS DOCUME... Ramon Linan
- RE: [ActiveDir] DN... Robinson, Chuck
- RE: [ActiveDir] DN... Scott, Anthony
- RE: [ActiveDi... Akomolafe, Deji
- RE: [Acti... joe
- RE: [... Akomolafe, Deji
