Share via

Active Directory Security

Gilberto Fernandez Garza 1 Reputation point
2021-08-06T22:25:26.927+00:00

Hi

I am working on a security guideline for Active Directory, however I haven't found a good reference to establish: (1) Minimum length for administrator password in AD and, (2) Expiration time of administrator accounts in AD

Do you know a best practice for these parameters?

Thanks

Regards

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
0 comments No comments

1 answer

Sort by: Most helpful
  1. Devaraj G 2,101 Reputation points Volunteer Moderator
    2021-08-07T09:17:07.36+00:00

    Hi @Gilberto Fernandez Garza , thanks for the post.

    Password and Account security guidelines is differ base on the organisation security and compliance requirements.

    standards like NIST, CIS, ISO are some of the security framework and guidelines for improving overall security and compliance based on org needs..

    Generally I would recommend to rename the default administrator account in AD to something to non obvious usernames instead of administrator and the rest will be configured through AD password policy domain level. Set password length to 14 with expiration of 60 days. Again this will change based on org needs and there are multiple other policy setting needs to be considering while setting the password policy for better security.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.