微软移除WIN10密码过期政策Microsoft Removes Password-Expiration Policy in Windows 10

Microsoft this week announced a series of changes to the security baseline in Windows 10, including the removal of the password-expiration policy from the platform.

Set to come into effect with the next Windows 10 feature update (Windows 10 version 1903, a.k.a. “19H1”) and Windows Server version 1903, the change is expected to have no impact on the security of the operating system.

Password expiration policies, Microsoft says, are only effective in the event a password is stolen during the validity interval and is used by an unauthorized party. However, if a password is never stolen, setting an expiration date for it makes no sense.

“And if you have evidence that a password has been stolen, you would presumably act immediately rather than wait for expiration to fix the problem,” Microsoft’s Aaron Margosis points out.

The baselines, he points out, are intended for use with “minimal if any modification by most well-managed, security-conscious enterprises. They are also intended to serve as guidance for auditors.”

Thus, an organization can choose other security policies to protect against stolen passwords instead of setting an expiration period, including banned-password lists, multi-factor authentication, detection of password-guessing attacks, and detection of anomalous logon attempts.

“Periodic password expiration is an ancient and obsolete mitigation of very low value, and we don’t believe it’s worthwhile for our baseline to enforce any specific value. By removing it from our baseline rather than recommending a particular value or no expiration, organizations can choose whatever best suits their perceived needs without contradicting our guidance,” Margosis says.

The proposed baselines (a draft is now available for download) also bring a change related to the built-in Administrator and Guest accounts. Up until now, these accounts have been disabled by default, but Microsoft is now removing this requirement from the security baselines.

“Note that removing these settings from the baseline would not mean that we recommend that these accounts be enabled, nor would removing these settings mean that the accounts will be enabled. Removing the settings from the baselines would simply mean that administrators could now choose to enable these accounts as needed,” Margosis explains.

The new baselines recommend having any administrative local accounts enabled, but only one of them should be in use and should have a strong password. The account can also be renamed, yet that doesn’t necessarily improve security.

Other changes Microsoft has announced include the enabling of a new “Enable svchost.exe mitigation options” policy to enforce stricter security on services hosted in svchost.exe; configuring the new App Privacy setting, “Let Windows apps activate with voice while the system is locked;” and disabling multicast name resolution (LLMNR) to mitigate server spoofing threats.

Vag COM , TCS CDP , VAS5054A , GM Tech2 , Iprog+ Programmer , Orange 5 programmer , SBB3 PRO3 Key Programmer , wiTech MicroPod II , T300+ Key Programmer, Iprog, Scania VCI3, mercedes star diagnostic, Porsche Piwis, vocom 88890300, Renault CAN Clip, SBB Key Programmer, NEXIQ USB Link

Other policies are meant to restrict the NetBT NodeType to P-node, disallowing the use of broadcast to register or resolve names; adding recommended auditing settings for Kerberos authentication service; dropping the specific BitLocker drive encryption method and cipher strength settings, and dropping the File Explorer “Turn off Data Execution Prevention for Explorer” and “Turn off heap termination on corruption” settings.

原文地址:https://www.cnblogs.com/cannovo/p/10777485.html

时间: 2024-10-26 13:42:53

微软移除WIN10密码过期政策Microsoft Removes Password-Expiration Policy in Windows 10的相关文章

Oracle 提示密码过期问题:the password will expire

SQL> conn scott/tiger ERROR: ORA-28002: the password will expire within 1 days Connected. SQL> conn /as sysdba Connected. SQL> alter user scott identified by tiger 2 ; User altered. SQL> conn scott/tiger Connected. SQL>

Windows 10 正式版本KMS激活key:Win10 TH1 Pro 10240.ESD专业、

10 正式版本KMS激活key:Win10 TH1 Pro 10240.ESD专业.企业.教育" title="Windows 10 正式版本KMS激活key:Win10 TH1 Pro 10240.ESD专业.企业.教育"> Windows 10 正式版本KMS激活key:Win10 TH1 Pro 10240.ESD专业.企业.教育版 基于Win10 TH1 Pro 10240.ESD  X86/X64专业.企业.教育版6合1 增强 制作 自动KMS Windows

简单几步制作 Windows 10 正式版U盘可启动安装盘图文教程 (全新安装Win10)

简单几步制作 Windows 10 正式版U盘可启动安装盘图文教程 (全新安装Win10) 相信不少朋友现在已经下载好 Windows 10 RTM 正式版的镜像文件了,虽然说微软提供了在原系统基础上升级的方式,但对于很多追求干净.稳定的朋友还是想要进行全新的安装的. 虽然将 Win10 系统的 ISO 镜像刻录成光盘来安装非常简单,但现在很多电脑已经不再配备光驱了,怎样制作 USB 的可启动 Windows 10 U盘安装盘成了很多同学的需求.今天吉他锅就给大家带来快速创建 Win10 启动安

【Windows 10 IoT】为Win10 IoT镜像添加默认应用(树莓派)

[Windows 10 IoT]为Win10 IoT镜像添加默认应用(树莓派) 在Windows 10 IoT应用程序开发好之后,一般通过IoT WebManagement或者直接用vs将应用部署上去.并且执行命令iotstartup.exe add headed/headless AppxID,将应用设置为开机启动.但是,如果想基于一个开发板,量产某种硬件设备,这种方式肯定是不可行的. 我们会想到,是否可以将我们的应用直接打包到镜像中,并设置成为开机自启的默认应用呢?当然可以. 基本原理是这样

微软Windows 10硬件新品发布会

微软用新一代硬件产品向外界展示了其在硬件设计生产方面的功力,丝毫不逊于任何硬件厂商,甚至用这些产品为其他第三方厂商制定了下一代设备的标准. 这些微软自家生产的硬件产品,无疑是展示Windows 10强大功能的最佳平台.无论是笔记本电脑.平板电脑.智能手机还是运动手环,实际上都是应用Windows10的平台,占领你的办公桌.客厅.卧室.健身房,甚至你的现实世界以外的想象空间. 发布会上首先公布了Windows 10的成绩,微软的最新一代操作系统Windows 10发布10周后,在全球已经有超过1.

Windows 10 上的 Git 如何清除密码? Git Credential Manager for Windows

Windows 10 上的 Git 如何清除密码? 因为一台新的电脑是 Windows 10 在第一次使用 Git 要求输入密码时把密码给输错了. 之前提交都是说 Token 错了,不再出现提示密码. 网上搜索一圈结果有一篇说在在 Git 中输出 git credential-manager uninstall 可以把密码清除. 然后厄运开始,每天 push 都要输出用户名和密码,密码倒是清除了,但是密码也不保存了. 后来搜索了才知道原因 credential-manager 是 Git Cre

PowerShell AD用户密码过期脚本更新版

越接触PowerShell感觉越喜欢这门脚本语言,简单易懂,功能强大,操作也方便,同时得益于微软的鼎力支持,在不同的微软产品平台都可以使用,如果想研究微软这方面的东西,会点PowerShell绝对是好处多多. 之前也写了一些关于PowerShell的文章,也相当于是自己不断摸索的过程,最近也陆陆续续写了一些脚本,有一些是工作环境里使用的,没办法拿出来分享,有一些是不同环境里都可以使用的,所以决定拿出来分享一下,脚本都很简单,写的也绝对算不上专业,只是基本的功能可以实现. 今天和大家分享的是写的一

微软发布的Win10开发者指南视频

如果你是一名开发者,建议你留意下微软今天推出的系列视频,名称是Win10开发者指南,总长6个小时,多达22章内容,介绍非常广泛.事实上,即使你是编程新手或仅有兴趣,也值得一看. 开发者Jerry Nixon和Andy Wigley是主持人,展示了渊博的知识和轻松的风趣幽默. 随着Windows10正式版越来越近,几乎可以肯定的是,其他平台的开发人员也会涌入.因此Win10开发者指南会让这些开发者尽快熟悉Windows10系统,更加轻松实现移植.作为微软虚拟学院的一部分,允许开发人员浏览各种技术文

AD密码过期查询

1. 查询单个账号是否过期:可以使用命令net user %USERNAME% /domain来进行查询.具体操作方式如下: 2.查询所有活动的AD账号密码过期时间:在AD域控上运行powershell工具. 第一步输入: $maxPasswordAge = (Get-ADDefaultDomainPasswordPolicy).MaxPasswordAge.Days 第二步输入: Get-ADUser -filter {Enabled -eq $True -and PasswordNeverE