Microsoft erkendte, at politik password aldring er ineffektiv

Microsoft har besluttet at træde væk fra politik, password aldring, der tvang brugerne til at ændre gemte adgangskoder fra tid til anden.

Technical giant presented new project plan of basic configuration settings for Windows 10 v1903 (19H10) og Windows Server v1903, der ville fjerne behovet for at ændre password hver uger eller måneder på konti, der er under koncernens politik.

Innovation will be implemented in Windows 10 Update that would be released in May 2019.

As Microsoft explains in its blog, existing policy “ancient and outdated, with little value” and company does not “consider it reasonable”. Algorithm of passwords aging that demands periodic password changes is not a reliable method of account protection, especially remembering that if password was stolen it is necessary take measures immediately instead of waiting until it expires, note in a company.

After cancellation of password aging policy Microsoft recommends organizations to replace preset password expiration settings with newer and modern safety practices, For eksempel, with multifactorial authentication, methods of brutforce-attacks detection or with realization of prohibited passwords list.

imidlertid, company does not change recommendations on minimal length and complicity of a password.

“To try to avoid inevitable misunderstandings, we are talking here only about removing password-expiration policies – we are not proposing changing requirements for minimum password length, history, or complexity.”, — emphasizes Microsoft experts.

Document also contains recommended policies concerning groups of users in corporate network, including rules that limit work of certain functions for abuse prevention, and blocking of certain functions that malware can exploit in attacks on system or network.

Kilde: https://blogs.technet.microsoft.com

Om Trojan Killer

Carry Trojan Killer Portable på din memory stick. Vær sikker på, at du er i stand til at hjælpe din pc modstå eventuelle cyber trusler, hvor du går.

Tjek også

MageCart på Heroku Cloud Platform

Forskere har fundet flere MageCart Web Forplove On Heroku Cloud Platform

Forskere ved Malwarebytes rapporteret om at finde flere MageCart web skummere på Heroku cloud-platform …

Android Spyware CallerSpy

CallerSpy spyware masker som en Android chat applikation

Trend Micro eksperter opdagede malware CallerSpy, hvilke masker som en Android chat program og, …

Skriv et svar