tailieunhanh - Microsoft Press mcts training kit 70 - 640 configuring windows server 2008 active directory phần 5
Trong thực tế, nó được áp dụng cuối cùng trong thứ tự chế biến, có nghĩa rằng các thiết lập của nó sẽ ghi đè lên các GPO 6 và 7. GPO để chế biến cho các Nhà thầu OU = 1, 3, 4, 5, 2 GPO chế biến thứ tự cho máy tính xách tay OU = 6, 7, 2 | Lesson 1 Configuring Password and Lockout Policies 359 If a user is determined to reuse a password when the password expiration period occurs he or she could simply change the password 25 times to work around the password history. To prevent that from happening the Minimum Password Age policy specifies an amount of time that must pass between password changes. By default it is one day. Therefore the determined user would have to change his or her password once a day for 25 days to reuse a password. This type of deterrent is generally successful at discouraging such behavior. Each of these policy settings affects a user who changes his or her password. The settings do not affect an administrator using the Reset Password command to change another user s password. Understanding Account Lockout Policies An intruder can gain access to the resources in your domain by determining a valid user name and password. User names are relatively easy to identify because most organizations create user names from an employee s e-mail address initials combinations of first and last names or employee IDs. When a user name is known the intruder must determine the correct password by guessing or by repeatedly logging on with combinations of characters or words until the logon is successful. This type of attack can be thwarted by limiting the number of incorrect logons that are allowed. That is exactly what account lockout policies achieve. Account lockout policies are located in the node of the GPO directly below Password Policy. The Account Lockout Policy node is shown in Figure 8-2. Figure 8-2 The Account Lockout Policy node of a GPO Three settings are related to account lockout. The first Account Lockout Threshold determines the number of invalid logon attempts permitted within a time specified by the Account Lockout Duration policy. If an attack results in more unsuccessful logons within that timeframe the user account is locked out. When an account is locked out Active Directory .
đang nạp các trang xem trước