Microsoft는 암호 노화의 정책이 효과가 인정

Microsoft는 강제로 사용자가 수시로 저장 암호를 변경할 것을 노화 암호 정책에서 멀리 단계로 결정.

echnical giant presented new project plan of basic configuration settings for Windows 10 v1903 (19H10) 및 Windows 서버 v1903, 암호 변경에 대한 필요성 그룹 정책 아래에 계정의 모든 주 또는 몇 달을 제거 할 것.

Innovation will be implemented in Windows 10 Update that would be released in May 2019.

As Microsoft explains in its blog, existing policy “ancient and outdated, with little value” and company does not “consider it reasonable". Algorithm of passwords aging that demands periodic password changes is not a reliable method of account protection, especially remembering that if password was stolen it is necessary take measures immediately instead of waiting until it expires, note in a company.

After cancellation of password aging policy Microsoft recommends organizations to replace preset password expiration settings with newer and modern safety practices, 예를 들면, with multifactorial authentication, methods of brutforce-attacks detection or with realization of prohibited passwords list.

하나, company does not change recommendations on minimal length and complicity of a password.

“To try to avoid inevitable misunderstandings, we are talking here only about removing password-expiration policies – we are not proposing changing requirements for minimum password length, history, or complexity.”, — emphasizes Microsoft experts.

Document also contains recommended policies concerning groups of users in corporate network, including rules that limit work of certain functions for abuse prevention, and blocking of certain functions that malware can exploit in attacks on system or network.

출처: https://blogs.technet.microsoft.com

폴리나 리소프스카야

저는 몇 년 동안 마케팅 관리자로 일하고 있으며 흥미로운 주제를 찾는 것을 좋아합니다.

회신을 남겨주

맨 위로 돌아가기 버튼