๐ Secure Bits ๐ก
๐ก๐ฒ๐ฒ๐ฑ ๐ ๐๐น๐๐ถ๐ฝ๐น๐ฒ ๐ฃ๐ฎ๐๐๐๐ผ๐ฟ๐ฑ ๐ฃ๐ผ๐น๐ถ๐ฐ๐ถ๐ฒ๐ ๐ถ๐ป ๐๐ฐ๐๐ถ๐๐ฒ ๐๐ถ๐ฟ๐ฒ๐ฐ๐๐ผ๐ฟ๐?
Many admins try to enforce different password rules via GPOs on OUs โ only to find out it doesnโt work.
๐ช๐ต๐?
๐น GPO password policy applies only to computer objects.
๐น Each domain supports only ONE account policy โ applied at the domain root.
So how do you apply different rules for different users?
โ
๐๐ถ๐ป๐ฒ-๐๐ฟ๐ฎ๐ถ๐ป๐ฒ๐ฑ ๐ฃ๐ฎ๐๐๐๐ผ๐ฟ๐ฑ ๐ฃ๐ผ๐น๐ถ๐ฐ๐ถ๐ฒ๐ (๐๐๐ฃ๐ฃ)
FGPP lets you create multiple password policies targeted at users or groups โ without touching your GPO password policy.
๐ก ๐๐
๐ฎ๐บ๐ฝ๐น๐ฒ ๐จ๐๐ฒ ๐๐ฎ๐๐ฒ:
๐น Users โ 12 characters (Enforced by GPO)
๐น Admins โ 17 characters (Enforced by FGPP)
๐ก ๐๐ผ๐ ๐๐ผ ๐๐ฒ๐ ๐ฝ๐ฎ๐๐๐๐ผ๐ฟ๐ฑ ๐น๐ฒ๐ป๐ด๐๐ต?
You can follow:
๐ธ CIS Benchmark:
โ 14 characters minimum
๐ธ NIST SP 800-63
โ 8 characters minimum
๐ธ Czech regulation (Vyhlรกลกka 82/2018):
โ Users โ 12 chars
โ Admins โ 17 chars
โ Service accounts โ 22 chars
FGPP is configured inย ๐๐ฐ๐๐ถ๐๐ฒ ๐๐ถ๐ฟ๐ฒ๐ฐ๐๐ผ๐ฟ๐ ๐๐ฑ๐บ๐ถ๐ป๐ถ๐๐๐ฟ๐ฎ๐๐ถ๐๐ฒ ๐๐ฒ๐ป๐๐ฒ๐ฟ.
๐ Want to learn more like this? ๐๐ต๐ฒ๐ฐ๐ธ ๐ผ๐๐ ๐ผ๐๐ฟ ๐๐ ๐๐ฒ๐ฐ๐๐ฟ๐ถ๐๐ ๐ฐ๐ผ๐๐ฟ๐๐ฒ:
๐ https://academy.horizon-secured.com/p/active-directory-password-policies
How are you handling password policies in your environment? ๐
