Click here to get back home

Keeping service accounts from locking

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Keeping service accounts from locking Scott Shoemaker 10-13-2006
Get Chitika Premium
Posted by Joe Richards [MVP] on October 22, 2006, 1:15 am
Please log in for more thread options
Special hardcoded functionality.

--
Joe Richards Microsoft MVP Windows Server Directory Services
Author of O'Reilly Active Directory Third Edition
www.joeware.net


---O'Reilly Active Directory Third Edition now available---

http://www.joeware.net/win/ad3e.htm


Scott Shoemaker wrote:
> OK,
> That is pretty much what I thought, but I appreciate the confirmation from
> Steve and yourself. So, how is it that the Administrator account is not
> subject to this policy?
>
> -Scott
>
> "Joe Richards [MVP]" wrote:
>
>> No you cannot set accounts to not lock. You either have the locking
>> policy or you don't. Some places will create an additional domain for
>> service accounts. A better solution is to use network service or local
>> service instead of userids or as Steve suggests get away from using
>> lockouts at all or change your use of them.
>>
>> If you must have lockouts, consider switching to a short lockout
>> duration so that a lockout on the account doesn't completely black out
>> the service. This is an attack vector as indicated by Steve.
>>
>> joe
>>
>> --
>> Joe Richards Microsoft MVP Windows Server Directory Services
>> Author of O'Reilly Active Directory Third Edition
>> www.joeware.net
>>
>>
>> ---O'Reilly Active Directory Third Edition now available---
>>
>> http://www.joeware.net/win/ad3e.htm
>>
>>
>> Scott Shoemaker wrote:
>>> Hi,
>>> We have a domain policy which dictates that locked accounts stay locked
>>> until they are unlocked. Last week, a domain account that is used to run a
>>> service got locked and brought an application down. So, is there any way to
>>> specifiy on an individual account that it should not be locked? As a follow
>>> on question, how is this accomplished on the Administrator account?
>>>
>>> Thanks,
>>> Scott

Similar ThreadsPosted
Hacker locking my accounts March 16, 2008, 5:02 pm
passwords Service accounts and services August 15, 2006, 6:41 pm
Disabling Interactibg Login for Service Accounts April 24, 2006, 8:14 pm
Restricting service accounts that have administrator privileges July 8, 2007, 12:10 pm
Additional restrictions for unprivileged service accounts July 11, 2007, 12:23 pm
Safe Keeping passwords July 6, 2005, 9:53 pm
Local Accounts vs Domain Accounts April 14, 2006, 3:48 pm
Priority: Users Home Laptops Brought In To Work (keeping them off company network) December 26, 2006, 12:13 pm
Administrator account locking out April 1, 2006, 9:22 am
Locking folders but NOT files. How? January 5, 2007, 9:20 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap