Using Active Directory to Specify Maximum Password Age

To enhance security, you can specify that passwords expire after a certain number of days. To specify a maximum password age for a user password, specify the password-management command in tunnel-group general-attributes configuration mode on the security appliance and do the following steps under Active Directory:

Step 1 Select Start > Programs > Administrative Tools > Domain Security Policy > Windows Settings > Security Settings > Account Policies > Password Policy.

Step 2 Double-click Maximum password age. This opens the Security Policy Setting dialog box.

Step 3 Check the Define this policy setting check box and specify the maximum password age, in days, that you want to allow.

Figure 30-3 Active Directory—Maximum Password Age

^ Domain Security Policy

-ln| x|

Action View

IB

m

_| Windows Settings

- jl Security Settings

Account Policies Password Policy Account Lockout Policy Kerberos Policy + Local Policies + Event Log + Restricted Groups + System Services + Registry + File System + _| Public Key Policies

BjijEnforce password history mo] Maxim urn password age .^Minimum password age ¡¡•¡Minimum password length ¡¡^Passwords must meet complexity requirements ore password using reversible encryption f,.,

I Computer Setting"

0 passwords remembered 2 days

1 days

7 characters

Disabled

Disabled

Tree

_| Windows Settings

- jl Security Settings

Account Policies Password Policy Account Lockout Policy Kerberos Policy + Local Policies + Event Log + Restricted Groups + System Services + Registry + File System + _| Public Key Policies

BjijEnforce password history mo] Maxim urn password age .^Minimum password age ¡¡•¡Minimum password length ¡¡^Passwords must meet complexity requirements ore password using reversible encryption f,.,

I Computer Setting"

0 passwords remembered 2 days

1 days

7 characters

Disabled

(security Policy Setting

JJ^

j^j Maximum password age

Define this policy setting

Passwords expire in: 2 -r| days

OK Cancel

Note The radius-with-expiry command, formerly configured as part of tunnel-group ipsec-ra configuration to perform the password age function, is deprecated. The password-management command, entered in tunnel-group general-attributes mode, replaces it.

Continue reading here: Using Active Directory to Enforce Minimum Password Length

Was this article helpful?

0 0