Solved

Windows 2012 Domain - Password Sharing Issue - reluctant humans!

Posted on 2016-11-22
4
53 Views
Last Modified: 2016-11-28
Hi
I have been looking at password complexity, expiry and all sorts of things best-practice-related and I have implemented a few additional policies on length, special characters, expiry etc..

...but I have a far more simple issue i would like to solve.... and i think it's a human one, but thought I'd check!

I have a department where the manager is insistent that it's easier for him to tell all his staff all to use the same password, Not the same user name, but same password for every user.  
Let's say that password does meet our complexity requirements, and as an example it's 1M4r1@UR!1  (That is example only, not one of my passwords).

In the manager's view, if  e.g. BOB is off sick, anyone else can log onto his PC and get to any work-in-progress, email etc,  as any other user would know that all they need to do is put in the user name and then the password that they all know.  

I can see his reasons, and I sympathise, but I don't agree with it.

In my view, this gives any user the chance to log on as anyone else and compromise their data and their email.  This might not (hopefully) include any existing member of staff, but you never know what drives people, and especially : what if someone leaves?  They may leave in anger, dispute, fired etc.  This then gives them the ability to log on from outside on Outlook Web and randomly delete any other user's email inbox.  This is especially easy in this manager's department as he insists on all staff using the same password, as I said above, but also when they change the password he merely adds a number sequence to the end of it, so for example 1M4r1@UR!1 becomes 1M4r1@UR!2, 1M4r1@UR!3 etc.

Yes, it's easier for his staff to remember BUT it's too easy for a disgruntled employee to guess/log on.

We are about to issue a company-wide policy on this but - just to check - can I enforce this in any way on Windows 2012?  I don't think it's possible for the system to know if two users have the same password?  It sounds more logical/secure that the system wouldn't be able to compare two users' passwords.

So, just to check before i send the written note out about this.

Over to you guys......
0
Comment
Question by:Malc
4 Comments
 
LVL 95

Assisted Solution

by:Lee W, MVP
Lee W, MVP earned 125 total points
ID: 41897626
one way to pseudo enforce this is have a long (initially) minimum password age. Then force each user to change their password but at staggered times.  user1 on Monday, 2 on tuesday, etc.  with a minmum password age near the maximum password age, if they forget, they need to reset with IT but it prevents them from all changing to the same password.
0
 
LVL 36

Assisted Solution

by:Geert Gruwez
Geert Gruwez earned 125 total points
ID: 41897977
why not show this manager what could happen ...

login with his account and send an invitation to the whole company for a party ... and he's paying
2
 
LVL 78

Accepted Solution

by:
David Johnson, CD, MVP earned 250 total points
ID: 41898248
it is a human problem, you will have to go higher up the organization to fix this.  What is wrong with allowing a team member to  call the help desk and get the password reset when someone is sick, when the person comes back also do the password reset?
1
 

Author Closing Comment

by:Malc
ID: 41903710
Thanks for confirming this is definitely a human policy issue, not an electronic one.
0

Featured Post

Free Trending Threat Insights Every Day

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

Join & Write a Comment

In my previous Experts Exchange Articles (http://www.experts-exchange.com/ARTH_1864316.html?arthOrderBy=3&arthSort=1#arth), most have featured Basic and Intermediate VMware Topics.  As a Virtualisation Consultant, we implement many different virtual…
My GPO's made for 2008 R2 servers were not allowing me to RDP into a new 2012 server by default.  That’s why I tried to allow RDP via Powershell, because I could log into a remote shell without further configuration. Below I will describe how I wen…
This tutorial will walk an individual through the process of installing the necessary services and then configuring a Windows Server 2012 system as an iSCSI target. To install the necessary roles, go to Server Manager, and select Add Roles and Featu…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

760 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

21 Experts available now in Live!

Get 1:1 Help Now