Re: SBS 2003 Administrator account lockout



But that's the idea of "denial of service". Pound ALL the accounts until all
are locked out.
If there's no automatic "unlock after x minutes", then you are .... hosed.

That's the reason the default Administrator account is exempt.

--
/kj
"Phantom" <private@xxxxxxxxx> wrote in message
news:7D6F8DC6-6710-477B-A55B-6F4C48BF7725@xxxxxxxxxxxxxxxx
That's the idea. Defeat Brute Force password guessing by locking the
account.

I have two additional accounts with Admin privledges using different
username/password conventions to unlock any disabled accounts.

"Susan Bradley, CPA aka Ebitz - SBS Rocks" wrote:

What ports do you have open to the web? All someone has to do is bang
on that account enough to lock it out.

Now how do you get in to unlock it if they are password guessing on it
and locking it out?


.



Relevant Pages

  • Re: Remote password change/account unlock
    ... Allowing users to change or reset their passwords or unlock their accounts ... There are security implications to having a service running as ...
    (microsoft.public.win2000.security)
  • Re: How 2 confirm delegation?
    ... How are you trying to unlock and/or reset accounts? ... > delegated control of a group to this new security group ...
    (microsoft.public.exchange2000.active.directory.integration)
  • Re: Account lockouts
    ... Not sure why you didn't find the lockouts in your logs. ... look at the free windows tools and look for unlock. ... quickly give you a list of all locked out accounts in a domain, ... > the outlook address book and attempts to log on to active directory. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Righs to unlock accounts:Set "read/write accountlockout" time, but option is still gra
    ... > I need to allow helpdesk to 'unlock' accounts under a certain OU. ... > then click Delegate Control from the menu that is displayed. ... The Delegation of Control Wizard should be displayed. ...
    (microsoft.public.win2000.active_directory)
  • Re: unlock user accounts en masse
    ... I have a sample program to find out if a given user is locked out, ... and then allow the user to unlock the account linked here: ... here is a sample program to document all accounts ... You might want to use a program that lists all locked out users, ...
    (microsoft.public.windows.server.scripting)