Share via

User credentials

IT_RACK5500 21 Reputation points
2021-07-31T14:58:41.367+00:00

Hi,

We have always been going with static password and never changed a user's password. I know this is one of the most wrong and dangerous practice but this is how the management wanted it to be. Now we got the go ahead to change the password every 2 months.

We also keep the passwords for all the users so that we can log in as the user when need be to troubleshoot.

My questions are as follows:

(1)If we allow the user to change the password, how can we log in as the user to trouble shoot?

(2)Is it legal to keep the users credentials ?

Just wanted to add that we are using Exchange

Thanks

Tazio

Exchange | Exchange Server | Management
Exchange | Exchange Server | Management

The administration and maintenance of Microsoft Exchange Server to ensure secure, reliable, and efficient email and collaboration services across an organization.


Answer accepted by question author

Andy David - MVP 160.3K Reputation points MVP Volunteer Moderator
2021-07-31T17:41:22.213+00:00

Not ever changing a user's password is not an issue. And changing the password every two months doesn't protect you.
Not using multi-factor authentication is a problem and should be where your focus should be:

https://learn.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-getstarted

If you aren't using Azure, consider a hybrid solution with Azure or a third party solution

This isnt really an Exchange issue however.

There is absolutely no reason to keep any user credentials. Has nothing to do with legality, there is simply no reason to do this.
If you need to troubleshoot a users mailbox, an admin can give yourself permission to it:

https://support.microsoft.com/en-us/topic/how-to-grant-exchange-and-outlook-mailbox-permissions-in-office-365-dedicated-bac01b2c-08ff-2eac-e1c8-6dd01cf77287#bkmk_1

Personally, I would never work for a company that required me to provide my password to them.

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

1 additional answer

Sort by: Most helpful
  1. IT_RACK5500 21 Reputation points
    2021-08-10T18:55:08.267+00:00

    Thanks a lot for your answers

    Tazio

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.