Lead Image © Nah Ting Feng, 123RF.com

Lead Image © Nah Ting Feng, 123RF.com

Lithnet Password Protection for Active Directory

P@ssw0rdis@s3cr3t!

Article from ADMIN 69/2022
By
Lithnet Password Protection for Active Directory provides flexible rules beyond that possible with group policies alone and prevents the use of previously compromised passwords.

Multifactor authentication (MFA) is the state of the art for securing user accounts and has long been recognized as such, ultimately even by users who are less IT savvy, now that numerous online services offer or even enforce MFA procedures. One service that many users encounter on a daily basis, however, usually only supports the traditional method of username and password: The security of an Active Directory infrastructure is defined by user account passwords. The free Lithnet Password Protection for Active Directory (LPP) provides more flexible rules than would be possible with group policies alone and prevents the use of previously compromised passwords. In this article, I look into how to commission and use LPP.

Length vs. Complexity

What constitutes a secure password and how often it should be changed is hotly debated among IT security experts worldwide. The consensus is that complexity and length are the decisive factors. The German Federal Office for Information Security (BSI) compares the two factors in its guidelines [1]. For example, the BSI recommends a high level of complexity for short passwords with a length of only eight to 12 characters. This typically means using four character types, of which many users will be familiar: a mix of upper- and lowercase letters, numbers, and special characters. The recommendations also lower the complexity requirements as the length increases. A significantly longer password with 20 to 25 characters may only have to meet two of the four complexity requirements. Indeed, the US National Institute of Standards and Technology (NIST), in the 2021 update to password guidance determined that length, "character for character," was more important than complexity [2].

The computational effort required to crack a password increases

...
Use Express-Checkout link below to read the full article (PDF).

Buy this article as PDF

Express-Checkout as PDF
Price $2.95
(incl. VAT)

Buy ADMIN Magazine

SINGLE ISSUES
 
SUBSCRIPTIONS
 
TABLET & SMARTPHONE APPS
Get it on Google Play

US / Canada

Get it on Google Play

UK / Australia

Related content

comments powered by Disqus