Re: disabled vs expired




Ok, first there is a difference between disable and expire as far as AD
goes. If you look at just backups, you will see a difference. Backing
up an Exchange email account that is disabled, will fail every time,
but if you expire it you will get a good backup. Expire stops only that
user from having access. Disable will stop all users for having access.
Also, email still comes into the mailbox on an expired user account.
This my be needed also, for lots of reasons.

Why use expire? The person has left, you want them to not be able to
get into their account, but you still need the supervisor/legal to
review the email in the account. Then use expire.

You can use expire like disable, just set the date older then today if
you want to stop access by the user. Granted disable is very fast and
you get to see the little red X next to the name. I would kill to have
a symbol next to expired accounts. As a side note, when we do expire an
account, well will add "- Expired" in the user description. If it is set
to expire on a set date, the we will add in the description "- Expire on
??/??/??". This is only for easier finding and admin reasons.

We only use disable if we want a fast stop of all user access. It will
be followed by changing it to expired as time permits. Most of the time
we just use expire.


--
fireater
------------------------------------------------------------------------
fireater's Profile: http://forums.techarena.in/member.php?userid=14440
View this thread: http://forums.techarena.in/showthread.php?t=74142

Free Computer Help - http://forums.techarena.in

.



Relevant Pages

  • Re: Force password reset for administrator
    ... When I logon to an account where the password has ... Except if the account is set so that "Password never expires", ... Microsoft MVP Scripting and ADSI ... expired, your code would configure so passwords no longer expire. ...
    (microsoft.public.scripting.vbscript)
  • Re: /etc/default/passwd and SSH
    ... SYNOPSIS: Description of "Password Aging" ... The warn field is the number of days of warning the user gets on login ... the expire field perform very distinct functions that are in no way related. ... The account should be disabled after a week so that it can not ...
    (Focus-SUN)
  • Re: expired passwords
    ... To expire a password for a user and then try to log back in for that ... You must change your password now and login again! ... If password aging has been enabled for your account, ... you don't actually know if you typed an incorrect username or an incorrect password. ...
    (Fedora)
  • Re: Force password reset for administrator
    ... My script is in fact doing the same as yours. ... Is also required to set the password reset bit. ... logf.WriteLine(" Set administrator account to password changed after next ... expired, your code would configure so passwords no longer expire. ...
    (microsoft.public.scripting.vbscript)
  • Re: Security Alert: Windows 2000 Expired Password Vulnerability
    ... I have never seen a password expire for a windows user account where there ... You might check your policy again. ... I am not familiar with Norton vpn client but with the built in W2K/XP Pro ...
    (microsoft.public.win2000.security)