Re: 154501--disable wkstn pswds

From: Laura E. Hunter \(MVP\) (hunter(nospamplease)_at_sfs.upenn.edu)
Date: 09/27/04


Date: Mon, 27 Sep 2004 10:31:55 -0400

It's pretty easy, actually. An NT/2000/XP machine uses a password to
communicate with a windows domain just like a user account. The password
used by the computer account gets automatically changed every 7 days for NT,
30 days for 2000/XP.

If you set these passwords to never change, you're exposing yourself to
similar risks as if your user account passwords never expired - someone can
sniff the computer account password and use it to gain unauthorized access
to your network.

-- 
******************************
Laura E. Hunter - MCSE, MCT, MVP
Replies to newsgroup only
"Scott Klein" <scott_f_klein@rush.edu> wrote in message 
news:uWdEs2JpEHA.3552@TK2MSFTNGP15.phx.gbl...
> Can anyone please tell me the "security risks" mentioned in article 
> 154501.
> (http://support.microsoft.com/default.aspx?scid=154501
> )  if I decide to disable workstation password changes?
>
> 


Relevant Pages

  • Re: NTDS huge file
    ... For VERY rough estimates a User account is about 4k and ... a computer account is something under 1K. ... Offline Compaction is done in Directory Services Restore Mode ... directly copied so a large file set on one DC is not automatically ...
    (microsoft.public.windows.server.active_directory)
  • Re: lock down TS in SBS2003 Standard environment (for Sales Force)
    ... I would put the user account objects and the computer account ... that takes me to the next question - the TS computer account object ... Normally I would not hesitate to do this...but I am still learning ...
    (microsoft.public.windows.server.sbs)
  • Re: Deploying an msi application via group policy
    ... You can indeed publish and assign GPOs to user account objects while you can ... O*N*L*Y assign GPOs to computer account objects. ... When you assign the application via GPO to the computer account side then it ...
    (microsoft.public.win2000.active_directory)
  • Folder permissions based on computer name instead of user name
    ... folder based on specific user accounts or groups. ... you set the permissions based on a computer account or group? ... the computer account that is being used to access the server, ... We can easily determine which PCs by user account name have the ...
    (microsoft.public.windows.server.security)
  • RE: Reconnect client computers help.
    ... The computer account will have to be recreated. ... As far as the user account, that doesn't have to be deleted. ... Microsoft Windows Small Business Server 2003 ... Deploying and Managing Small/Medium Size Business 2003 - MCP ...
    (microsoft.public.windows.server.sbs)