• Password Policy: Password Must Meet Complexity Requirements

    by  • July 31, 2009 • Configuring Vista Security

    This security setting enforces password complexity to ensure that users create strong passwords that are not easily guessed or cracked.

    With Passwords Must Meet Complexity Requirements enabled, passwords must meet the following minimum requirements:

    • Must not contain the user’s account name or parts of the user’s full name that exceed two consecutive characters
    • Must be at least six characters in length (or the length specified in Minimum Password Length if that setting is higher than 6)
    • Must contain characters from three of the following four categories:
      • Uppercase characters (A through Z)
      • Lowercase characters (a through z)
      • Base 10 digits (0 through 9)
      • Special symbols or non-alphabetic characters (for example: !, $, #, %, etc.)

    Complexity requirements are enforced when passwords are changed or created.

    Defaults:

    • Enabled on domain controllers
    • Disabled on stand-alone servers

    Note: By default, PC’s on a network domain follow the configuration of their domain controllers.

    About

    Tony has driven security policies and technologies for antivirus and incident response for Fortune 500 companies, and he has been network administrator and technical support for smaller companies. He has written for a variety of other Web sites and publications, including BizTech Magazine, PC World, SearchSecurity.com, WindowsNetworking.com, Smart Computing magazine, and Information Security magazine. Tony is a CISSP (Certified Information Systems Security Professional) and ISSAP (Information Systems Security Architecture Professional). He is Microsoft Certified as an MCSE (Microsoft Certified Systems Engineer) and MCSA (Microsoft Certified Systems Administrator) in Windows 2000 and an MCP (Microsoft Certified Professional) in Windows NT. Tony has been recognized by Microsoft as an MVP (Most Valuable Professional) in Windows security since 2006. In addition to his Web site and magazine contributions, Tony was also tech editor of PCI Compliance (ISBN: 1597491659 ) and author of Essential Computer Security: Everyone’s Guide to E-mail, Internet, and Wireless Security (ISBN: 1597491144), coauthor of Hacker’s Challenge 3 (ISBN: 0072263040) and a contributing author to Winternals: Defragmentation, Recovery, and Administration Field Guide (ISBN: 1597490792), Combating Spyware in the Enterprise (ISBN: 1597490644) Syngress Force 2006 Emerging Threat Analysis: From Mischief to Malicious (ISBN: 1597490563), Botnets: The Killer Web Applications (ISBN: 1597491357), and AVIEN Malware Defense Guide for the Enterprise (ISBN: 1597491640).

    http://www.tonybradley.com