The contents of this instruction:
Password requirements AD
- Password length at least 12 characters.
- Must not contain username or display name.
- Must contain characters from three different categories:
-
- capital letters
- lower case
- result
- peculiars
-
- Password expiration time 365 days.
- Previous passwords are remembered for the previous 5, to which the password cannot be changed.
- Minimum password time 0 days.
Password Locking Policies for Entra ID logins
Locking Policy
- The ID locks after 10 incorrect passwords.
- Entering the same invalid password sequentially does not increase the counter.
- The user’s known login locations and the user’s new login locations have their own counter.
- The account is locked for 600 seconds and then opens automatically.
- If, after opening, the next login attempt is with the wrong password, the account will be immediately locked again.
- Repeated lockdowns increase the time of lockdown.
In addition to these rules, Microsoft’s Identity Protection feature is also used to identify anonymous IP addresses, password spray attacks, and known ID and password pair leaks from logins. Based on these, Identity Protection increases the risk level of a user or login.
Risk level of logins
If the risk level of login is marked as high for Identity Protection, a two-step authentication is always required.
Password Locking Policies for AD/LDAP logins
- The ID locks after 20 incorrect logins.
- The account is locked for 600 seconds and then opens automatically.
- False attempts counter resets after 10 minutes.
« Back
This article was published in categories English version available, All instructions, Oamk , for Oamk staff, for Oamk students, for the University of Oulu staff, for the University of Oulu students, accessible content, UniOulu and tags password, account, information security, käyttäjätunnus, locking policies, lukitsemiskäytännöt, password, computer security. Add the permalink to your favourites.