Lompat ke konten Lompat ke sidebar Lompat ke footer

Harden Windows Login Password Policy & Account Lockout Policy

To protect your computer from unauthorized use, Windows 11/10/8/7 provides a facility to protect it victimisation a password. A strong password is thus the initiatory line of defense as far as your information processing system's security is concerned.

If you bid to enhance the security of your Windows computer, you can beef up the Windows Login Password Insurance using the improved-in Local Security system Policy or Secpol.msc. Nested among its many settings is a useful set of options that leave allow you to configure the Password Policy for your computer.

Indurate Windows Login Password Policy

To staring and enjoyment the Local Security Policy open Run, typecast secpol.msc and hit Enter. In the left pane, clink on Account Policies > Password Policy. In the accurate window pane, you see settings for configuring the Password Policy.

These are some parameters that you rear configure. Double click on each to open their Properties corner. From the drop-cut down menu you can choose and select the desired option. Once you own set them, do not draw a blank to penetrate happening Apply/OK.

1] Enforce Watchword History

Using this insurance, you tail ensure that users bash not use old passwords over and over subsequently a while. This setting determines the number of unique new passwords that have to be associated with a user account statement before an old password can be reused. You backside set whatsoever value betwixt. The default is 24 along domain controllers and 0 on stand-alone servers.

2] Uttermost password age

You force out impel users to change their passwords after a particular list of days.  You can set passwords to expire after a number of years between 1 and 999, or you can specify that passwords never die off by setting the number of days to 0. The nonpayment is set at 42 days.

3]Minimum password age

Here you sack enforce the stripped flow that any password mustiness beryllium used before it can be changed. You can adjust a value between 1 and 998 days, or you can allow changes immediately by setting the number of days to 0. The default is 1 on demesne controllers and 0 along complete servers. While this stage setting may not go towards strengthening your password policy, if you wish to foreclose users from ever-changing passwords too oft, you may set this policy.

4] Minimum password length

This is an burning setting and you may want to enforce IT to forbid hack attempts. You can set a value of between 1 and 14 characters, OR you can establish that no password is obligatory by setting the number of characters to 0. The default is 7 on domain controllers and 0 on stand-alone servers.

You fanny also take to Enable two Thomas More settings if you wish. Once you have opened their individual Properties boxes, select Enabled and Practice to enable the insurance policy.

5] Watchword must touch complexity requirements

Another important setting you want to use as it testament make passwords more than Byzantine and hence hard-fought to compromise. If this policy is enabled, passwords must encounter the following borderline requirements:

  1. Not contain the user's explanation cite or parts of the exploiter's stuffed name that exceed two consecutive characters
  2. Be at least six characters in length Hold characters from three of the following four categories:
  3. English upper-case letter characters (A through and through Z)
  4. English lowercase characters (a through z)
  5. Base 10 digits (0 through 9)
  6. Non-alphabetic characters (for model, !, $, #, %)

6] Store passwords using reversible encryption

This surety setting determines whether the operating system stores passwords using reversible encryption. Storing passwords using reversible encryption is essentially the same as storing plain-text versions of the passwords. For this reason, this policy should never cost enabled unless application requirements outweigh the call for to protect password info.

Read: How to customize the Password Insurance policy in Windows.

Account Lockout Policy in Windows 11/10

To further fortify the Password Policy, you can also set the lockout durations and thresholds, as this will stop electric potential hackers in their tracks after a particular identification number of failed attempts. To configure these settings, in the left Elvis, click on Account Lockout Policy.

1] Account lockout threshold for Invalid logins

If you located this policy, you tooshie master the identification number of null logins. The default is 0 but you arse set a figure between 0 and 999 failed logon attempts.

2] Describe lockout duration

Using this setting, you can fix the number of minutes a locked-kayoed account remains locked unconscious before mechanically becoming unlocked. You tail set any figure 'tween 0 minutes and  99,999 minutes. This insurance policy has to set ahead along with the Account lockout threshold policy.

Read: Throttle the number of Login attempts in Windows.

3] Readjust account lockout counter later on

This security setting determines the number of transactions that moldiness slip away aft a failing logon try out before the failed logon attempt counter is reset to 0 bad login attempts. The available orbit is 1 minute to 99,999 minutes. This policy too has to set on with the Account statement lockout threshold policy.

Stay safe, stay secure!

Aware of AuditPol in Windows? If not, you might want to read about it.

Harden Windows Login Password Policy & Account Lockout Policy

Source: https://www.thewindowsclub.com/windows-login-password-policy

Posting Komentar untuk "Harden Windows Login Password Policy & Account Lockout Policy"