tailieunhanh - Protecting SAM and Security Hives phần 2

Recommended Settings for the Account Lockout Policy Description Recommended setting The number of minutes a locked-out account will stay 30 minutes locked out. If this is set to 0 | Table Recommended Settings for the Account Lockout Policy Setting Description Recommended setting Account The number of minutes a locked-out account will stay 30 minutes lockout locked out. If this is set to 0 the account will have to be duration unlocked by an administrator or someone who has been given the right to do so. Account The number of incorrect attempts at guessing a password 5 invalid logons lockout that can be made before the account is locked out. threshold Reset The number of minutes after which the count of invalid 10 minutes account logon attempts will be reset. If the number of minutes lockout between one invalid logon and another is greater than the counter after number of minutes to which this setting is configured the previous invalid logon attempts won t matter. Note A good password policy is essential to network security but unfortunately it is often overlooked. Here are several tips about the worst practices that you should avoid under all circumstances Do not create local Administrator accounts or common domain-level administrator accounts using a variation of the company name computer name advertising tag lines or dictionary words such as o ocompanyname o 1 wiri2ko ocompanyname o etc. Do not create new user accounts with simple passwords that aren t required to change the password after the first logon. Be aware that none of the above-described settings can force your end users to create strong passwords. Similarly even the strongest password policy can prevent users from writing down their passwords and attaching a note to their monitors sharing passwords with other users or complaining to management when they have to get help to reset a password they have forgotten. Protecting the Local Administrator Account When your Windows NT-based system is joined to a domain the local Administrator account is still present as was already mentioned it resides in SysZemRooZ System32 Config SAM . Actually members of the Domain Admins group can .

crossorigin="anonymous">
Đã phát hiện trình chặn quảng cáo AdBlock
Trang web này phụ thuộc vào doanh thu từ số lần hiển thị quảng cáo để tồn tại. Vui lòng tắt trình chặn quảng cáo của bạn hoặc tạm dừng tính năng chặn quảng cáo cho trang web này.