Protect user accounts

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: timpuri (anonymous_at_discussions.microsoft.com)
Date: 05/29/04


Date: Sat, 29 May 2004 11:15:25 -0700

Hi

In a singe-domain, single - forest impementation. How am I
able to protect useraccounts from hacking. For example: I
have a ou1 with users. I have another ou2 with users. I
have a security policy that locks user account after 5
failed logon attemps. Now if users in ou2 somehow would
get to know (or guess) another username from ou1 and they
wanted to do harm, they intentionally make five failed
logons as a user in ou1 and the account is locked.
I know
- we can define the computers netbios name, where user
only can logon
- we can make gpos "log on locally"
- we can make restricted group policy

But still. If you are in the same domain and you know the
username, you can try to logon and DCs' do as if defined
in the domain policy.

Thanks

Timo



Relevant Pages

  • Re: Protect user accounts
    ... Enable strong passwords in the password policy, ... this helps to protect in that way if some one take over an account the ... users in OU1 to computers in OU2 and the other way around. ... > failed logon attemps. ...
    (microsoft.public.windows.server.active_directory)
  • Restricting logon attempts
    ... I have a ou1 with users. ... I have a security policy that locks user account ... after 5 failed logon attemps. ... try to logon and DCs' do as if defined in the domain policy. ...
    (microsoft.public.windows.server.active_directory)
  • RE: Cant set Local Security policies. They fail to save
    ... predefined Security Template on SBS 2003 to restore security groups ... run "gpupdate.exe /force" under command prompt to force the policy ... reboot the Server to test. ... and then logon to client computer to test if user can save system logs. ...
    (microsoft.public.windows.server.sbs)
  • RE: Event ID 537 and Kerberos
    ... a logon type of 3 translates to Network. ... Click Services tab and select Hide All Microsoft Services and Disable ... Step 4: Configure account lockout policy. ... and then click Account Lockout Policy. ...
    (microsoft.public.windows.server.sbs)
  • Re: Remote Client Configuration
    ... Thanks for quickly updates. ... Just as I know, if you only logon the domain with cache credential, the ... group policy will not be updates, instead it will use the old policy that ... dial up VPN connection to logon SBS domain once-in-a-while for the group ...
    (microsoft.public.windows.server.sbs)