Lockout inactive AD Accounts

Tech-Archive recommends: Fix windows errors by optimizing your registry

From: Eric (Eric_at_discussions.microsoft.com)
Date: 12/06/04


Date: Mon, 6 Dec 2004 08:59:09 -0800

I've gone through the security policies for accounts in AD 2003. I can't
find a lockout policy for inactive accounts. I'm assuming that means I
woudl have to look at 3rd party soluitions. I want to lockout accounts that
are inactive after a specified period of time. My questions are: am I
missing something and this can be done or do you know of any 3rd party addons
that can do this? (I looked at NETIQ, but that doesn't fit the bill).

Thank you



Relevant Pages

  • Re: Lockout inactive AD Accounts
    ... >find a lockout policy for inactive accounts. ... >woudl have to look at 3rd party soluitions. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Account lockouts
    ... First off you can't disable lockout policy for specific accounts, it is a domain wide setting. ... Second, enable auditing on your domain controllers and member servers, specifically the logon failures auditing ...
    (microsoft.public.win2000.security)
  • Re: Password Change Utility
    ... We do already have a lockout policy created... ... service desk is required to unlock accounts. ... >> password and display a 128 bit encrypted web page ...
    (microsoft.public.win2000.security)
  • Re: Accounts getting locked
    ... the GPO at the top of the list has precedence for defined settings. ... "net accounts" on a domain controller to see what it reports for lockout policy. ... Local user accounts may have a different lockout policy than domain accounts if ...
    (microsoft.public.win2000.group_policy)
  • about inactive account hijacking
    ... email service provider delete inactive accounts after six or twelve months of inactivity and release the adresse ... This asymmetry in handling inactive accounts has the consequence that thousands of accounts of various online platforms can be hijacked by attackers without any technical difficulties. ... Then the attacker tries at a variety of online platforms to create accounts for the just mentioned email address. ...
    (Bugtraq)