500+ users here and am a big fan of account lockout durations of less than 5 minutes. Our annual security assessment advisor didn't like that very much, for reasons i'm still attempting to figure out. I've read several pieces of documentation suggesting keeping the lockout duration to even about 1 minute would be secure, but I'm far from an info sec expert. I'm eager to hear from the folks on this list who disagree with the lockout duration being set to anything higher than 5 minutes (for arguments sake).
Harry. On Thu, Feb 16, 2012 at 7:22 PM, Kurt Buff <[email protected]> wrote: > Well, since you're that understaffed, I'd personally set the timeout > to 5 minutes, and let the students deal with it. I say that wearing my > BOFH hat, but I don't think that it's all that unreasonable. > > On Thu, Feb 16, 2012 at 14:50, Blackman, Woody <[email protected]> > wrote: > > Well, in an academic environment, we have 35,000 students per semester > using about 2,000 resources (computers in labs) and about 6 people per > shift to "help" them. They need access and we need automation/self-service > wherever there is opportunity. > > > > -----Original Message----- > > From: Kurt Buff [mailto:[email protected]] > > Sent: Thursday, February 16, 2012 2:37 PM > > To: NT System Admin Issues > > Subject: Re: Self-Service Account Unlock > > > > So, I have some questions regarding this: > > > > What is the rush on the part of the end user to have this done? They > can't wait 5 or 10 minutes for the unlock to happen automagically? > > > > How often do account lockouts happen that this is something worth > spending time and money on a solution? > > > > Frankly, with my user base of about 250 staff, I consider it unusual to > get as many as three requests in a month for account unlocks. > > > > Kurt > > > > On Thu, Feb 16, 2012 at 10:44, Sean Rector <[email protected]> > wrote: > >> I’ve been looking through the multitude of options, but they all seem > >> to be web-portal-based. Is there one that puts the Unlock option on > >> the Logon Screen? > >> > >> > >> > >> My point is – what’s the use of a web-portal version when they can’t > >> log on to their machine? A kiosk-type user account doesn’t seem the > >> safest route to go. > >> > >> > >> > >> Sean Rector, MCSE > >> > >> > >> > >> Information Technology Manager > >> Virginia Opera Association > >> > >> E-Mail: [email protected] > >> Phone: (757) 213-4548 (direct line) {+} > >> > >> Tickets and Subscriptions On Sale Now! > >> Orphée | The Mikado > >> Visit us online at www.VaOpera.org or call 1-866-OPERA-VA > >> > >> Experience the Beauty, Power & Passion of Virginia Opera. > >> > >> ________________________________ > >> > >> This e-mail and any attached files are confidential and intended > >> solely for the intended recipient(s). Unless otherwise specified, > >> persons unnamed as recipients may not read, distribute, copy or alter > >> this e-mail. Any views or opinions expressed in this e-mail belong to > >> the author and may not necessarily represent those of Virginia Opera. > >> Although precautions have been taken to ensure no viruses are present, > >> Virginia Opera cannot accept responsibility for any loss or damage > >> that may arise from the use of this e-mail or attachments. > >> > >> {*} > >> > >> ~ Finally, powerful endpoint security that ISN'T a resource hog! ~ ~ > >> <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/> ~ > >> > >> --- > >> To manage subscriptions click here: > >> http://lyris.sunbelt-software.com/read/my_forums/ > >> or send an email to [email protected] > >> with the body: unsubscribe ntsysadmin > > > > ~ Finally, powerful endpoint security that ISN'T a resource hog! ~ ~ < > http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/> ~ > > > > --- > > To manage subscriptions click here: > http://lyris.sunbelt-software.com/read/my_forums/ > > or send an email to [email protected] > > with the body: unsubscribe ntsysadmin > > > > > > ~ Finally, powerful endpoint security that ISN'T a resource hog! ~ > > ~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/> ~ > > > > --- > > To manage subscriptions click here: > http://lyris.sunbelt-software.com/read/my_forums/ > > or send an email to [email protected] > > with the body: unsubscribe ntsysadmin > > ~ Finally, powerful endpoint security that ISN'T a resource hog! ~ > ~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/> ~ > > --- > To manage subscriptions click here: > http://lyris.sunbelt-software.com/read/my_forums/ > or send an email to [email protected] > with the body: unsubscribe ntsysadmin > > ~ Finally, powerful endpoint security that ISN'T a resource hog! ~ ~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/> ~ --- To manage subscriptions click here: http://lyris.sunbelt-software.com/read/my_forums/ or send an email to [email protected] with the body: unsubscribe ntsysadmin
