<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Windows Server 'Longhorn': Granular Password Settings</title><link>http://msmvps.com/blogs/ulfbsimonweidner/archive/2007/03/12/windows-server-quot-longhorn-quot-granular-password-settings.aspx</link><description>I recently got permissions to blog about some of the features which are not as well known in the next version of Microsofts Server Operating System: Windows Server "Longhorn". So let's get started. One of them is that in Longhorn, you are not limited</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>http://msmvps.com/blogs/ulfbsimonweidner/archive/2007/03/12/windows-server-quot-longhorn-quot-granular-password-settings.aspx</title><link>http://msmvps.com/blogs/ulfbsimonweidner/archive/2007/03/12/windows-server-quot-longhorn-quot-granular-password-settings.aspx#1544543</link><pubDate>Sun, 16 Mar 2008 20:26:43 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1544543</guid><dc:creator>http://msmvps.com/blogs/ulfbsimonweidner/archive/2007/03/12/windows-server-quot-longhorn-quot-granular-password-settings.aspx</dc:creator><description>&lt;p&gt;Pingback from &amp;nbsp;&lt;a rel="nofollow" target="_new" href="http://msmvps.com/blogs/ulfbsimonweidner/archive/2007/03/12/windows-server-quot-longhorn-quot-granular-password-settings.aspx"&gt;msmvps.com/.../windows-server-quot-longhorn-quot-granular-password-settings.aspx&lt;/a&gt;&lt;/p&gt;
&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1544543" width="1" height="1"&gt;</description></item><item><title>Windows Server 2008 - Fine-Grained Password Policies</title><link>http://msmvps.com/blogs/ulfbsimonweidner/archive/2007/03/12/windows-server-quot-longhorn-quot-granular-password-settings.aspx#1099238</link><pubDate>Thu, 09 Aug 2007 21:20:22 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1099238</guid><dc:creator>Jorge 's Quest For Knowledge!</dc:creator><description>&lt;p&gt;In previous OSes if you wanted to create multiple password or account lockout policies you basically&lt;/p&gt;
&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1099238" width="1" height="1"&gt;</description></item><item><title>Active Directory Domain Services: Fine-grained Password Policies</title><link>http://msmvps.com/blogs/ulfbsimonweidner/archive/2007/03/12/windows-server-quot-longhorn-quot-granular-password-settings.aspx#1036050</link><pubDate>Wed, 18 Jul 2007 08:00:02 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1036050</guid><dc:creator>Kurt Roggen's blog</dc:creator><description>&lt;p&gt;[This information is based on the Windows Server 2008 June CTP and is subject to change...] Windows Server&lt;/p&gt;
&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1036050" width="1" height="1"&gt;</description></item><item><title>Free UI Console for Fine-Grained Password Policies &amp;laquo; Dmitry&amp;#8217;s PowerBlog</title><link>http://msmvps.com/blogs/ulfbsimonweidner/archive/2007/03/12/windows-server-quot-longhorn-quot-granular-password-settings.aspx#973698</link><pubDate>Tue, 19 Jun 2007 15:55:10 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:973698</guid><dc:creator>Free UI Console for Fine-Grained Password Policies « Dmitry’s PowerBlog</dc:creator><description>&lt;p&gt;Pingback from &amp;nbsp;Free UI Console for Fine-Grained Password Policies &amp;amp;laquo; Dmitry&amp;amp;#8217;s PowerBlog&lt;/p&gt;
&lt;img src="http://msmvps.com/aggbug.aspx?PostID=973698" width="1" height="1"&gt;</description></item><item><title>Manage Fine-Grained Password Policies with PowerShell &amp;laquo; Dmitry&amp;#8217;s PowerBlog</title><link>http://msmvps.com/blogs/ulfbsimonweidner/archive/2007/03/12/windows-server-quot-longhorn-quot-granular-password-settings.aspx#971304</link><pubDate>Mon, 18 Jun 2007 12:20:42 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:971304</guid><dc:creator>Manage Fine-Grained Password Policies with PowerShell « Dmitry’s PowerBlog</dc:creator><description>&lt;p&gt;Pingback from &amp;nbsp;Manage Fine-Grained Password Policies with PowerShell &amp;amp;laquo; Dmitry&amp;amp;#8217;s PowerBlog&lt;/p&gt;
&lt;img src="http://msmvps.com/aggbug.aspx?PostID=971304" width="1" height="1"&gt;</description></item><item><title>Window Server 2008 &amp;raquo; Windows Server 2008: Fine-grained password policies</title><link>http://msmvps.com/blogs/ulfbsimonweidner/archive/2007/03/12/windows-server-quot-longhorn-quot-granular-password-settings.aspx#956416</link><pubDate>Mon, 11 Jun 2007 16:28:33 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:956416</guid><dc:creator>Window Server 2008 » Windows Server 2008: Fine-grained password policies</dc:creator><description>&lt;p&gt;Pingback from &amp;nbsp;Window Server 2008 &amp;amp;raquo; Windows Server 2008: Fine-grained password policies&lt;/p&gt;
&lt;img src="http://msmvps.com/aggbug.aspx?PostID=956416" width="1" height="1"&gt;</description></item><item><title>4sysops -- Windows Server 2008: Fine-grained password policies</title><link>http://msmvps.com/blogs/ulfbsimonweidner/archive/2007/03/12/windows-server-quot-longhorn-quot-granular-password-settings.aspx#936293</link><pubDate>Thu, 31 May 2007 19:19:38 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:936293</guid><dc:creator>4sysops -- Windows Server 2008: Fine-grained password policies</dc:creator><description>&lt;p&gt;Pingback from &amp;nbsp;4sysops -- Windows Server 2008: Fine-grained password policies&lt;/p&gt;
&lt;img src="http://msmvps.com/aggbug.aspx?PostID=936293" width="1" height="1"&gt;</description></item><item><title>New in Longhorn Server - Active Directory Changes Part 2</title><link>http://msmvps.com/blogs/ulfbsimonweidner/archive/2007/03/12/windows-server-quot-longhorn-quot-granular-password-settings.aspx#894709</link><pubDate>Tue, 08 May 2007 14:21:43 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:894709</guid><dc:creator>Tech Talk Blog</dc:creator><description>&lt;p&gt;In this post I continue on from Part 1, examining new functionality in Active Directory coming with Longhorn...&lt;/p&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=894709" width="1" height="1"&gt;</description></item><item><title>Ziarniste polityki hasel</title><link>http://msmvps.com/blogs/ulfbsimonweidner/archive/2007/03/12/windows-server-quot-longhorn-quot-granular-password-settings.aspx#851510</link><pubDate>Sat, 21 Apr 2007 08:40:25 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:851510</guid><dc:creator>pkrzysz blog</dc:creator><description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=851510" width="1" height="1"&gt;</description></item><item><title>Ziarniste polityki haseł</title><link>http://msmvps.com/blogs/ulfbsimonweidner/archive/2007/03/12/windows-server-quot-longhorn-quot-granular-password-settings.aspx#787980</link><pubDate>Thu, 12 Apr 2007 11:01:23 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:787980</guid><dc:creator>Windows Server Code Name "Longhorn"</dc:creator><description>&lt;p&gt;Od lutowego CTP dostępne są ziarniste polityki haseł - czyli możliwość przypisywania polityk haseł do&lt;/p&gt;
&lt;img src="http://msmvps.com/aggbug.aspx?PostID=787980" width="1" height="1"&gt;</description></item><item><title>Windows Server "Longhorn" - Múltiplas Políticas de Senha</title><link>http://msmvps.com/blogs/ulfbsimonweidner/archive/2007/03/12/windows-server-quot-longhorn-quot-granular-password-settings.aspx#761707</link><pubDate>Fri, 06 Apr 2007 14:53:47 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:761707</guid><dc:creator>Segurança na Microsoft</dc:creator><description>&lt;p&gt;Uma limita&amp;#231;&amp;#227;o conhecida do Active Directory &amp;#233; a de ele suportar somente uma &amp;#250;nica pol&amp;#237;tica de senhas&lt;/p&gt;
&lt;img src="http://msmvps.com/aggbug.aspx?PostID=761707" width="1" height="1"&gt;</description></item><item><title>Last CTP Before Beta 3</title><link>http://msmvps.com/blogs/ulfbsimonweidner/archive/2007/03/12/windows-server-quot-longhorn-quot-granular-password-settings.aspx#759071</link><pubDate>Thu, 05 Apr 2007 22:58:49 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:759071</guid><dc:creator>Windows Server Division WebLog</dc:creator><description>&lt;p&gt;Late on Wednesday, as part of our commitment to deliver regular updates of Windows Server &amp;quot;Longhorn&amp;quot;&lt;/p&gt;
&lt;img src="http://msmvps.com/aggbug.aspx?PostID=759071" width="1" height="1"&gt;</description></item><item><title>Windows Server Longhorn – Functional Levels</title><link>http://msmvps.com/blogs/ulfbsimonweidner/archive/2007/03/12/windows-server-quot-longhorn-quot-granular-password-settings.aspx#691929</link><pubDate>Sun, 18 Mar 2007 21:25:26 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:691929</guid><dc:creator>Jorge 's Quest For Knowledge!</dc:creator><description>&lt;p&gt;Windows Server Longhorn will support three forest functional levels: Windows 2000 &amp;#224; W2K DCs and higher&lt;/p&gt;
&lt;img src="http://msmvps.com/aggbug.aspx?PostID=691929" width="1" height="1"&gt;</description></item><item><title>re: Windows Server 'Longhorn': Granular Password Settings</title><link>http://msmvps.com/blogs/ulfbsimonweidner/archive/2007/03/12/windows-server-quot-longhorn-quot-granular-password-settings.aspx#691301</link><pubDate>Sun, 18 Mar 2007 13:42:16 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:691301</guid><dc:creator>Guido Grillenmeier</dc:creator><description>&lt;p&gt;Nice post Ulf - this comment is similar to what I posted on ActiveDir.org where this feature is also being discussed right now. The discussions often mention the need of a UI to manage it. &lt;/p&gt;
&lt;p&gt;I don’t think that administrators will need much of a UI to configure password policy – a useful cli-tool should do, as I don’t see this used for too many different policies in a company. &amp;nbsp;There may be exceptions where companies want to configure extra strong policies for (non-admin) users working with more sensitive data, but I don’t expect more than maybe 3-5 policies in most companies (…keep it simple…)&lt;/p&gt;
&lt;p&gt;So while the challenge is not necessarily configuring the policies (even works quite fine with ADSIedit – you only have to get over the time-conversion quirk), it will certainly be understanding the active policy for a specific user, for example when a user calls the helpdesk because he or she has an issue setting a new password… &amp;nbsp;(I can hear them already asking the helpdesk why his 8 char password is not accepted…) How will the helpdesk know which policy applies to the user? What if it’s one that doesn’t have the default domain policy but instead is member of a group that a specific Password Settings Object (PSO) has been applied to?&lt;/p&gt;
&lt;p&gt;This info is easy to retrieve, but it’s not available easily in the current UIs - the following two attributes will retrieve the required data:&lt;/p&gt;
&lt;p&gt;* ms-DS-PSO-Applied =&amp;gt; this is a Backlink attribute of a user or group object (corresponds to the ms-DS-PSO-AppliesTo ForwardLink of the respective PSO object) and returns the DN of all the PSOs that are directly linked with the user or group. Note that multiple policies can be applied to a user or group and you’d need to run a query over the various groups and nested groups to determine all the PSOs that are applied directly and indirectly to a user and then evaluate the one with the highest priority/precedence. You’d first want to check If a policy is applied directly to a user as this always takes precedence over any policy applied via a group.&lt;/p&gt;
&lt;p&gt;* ms-DS-Resultant-PSO =&amp;gt; this a constructed attribute for users that return the DN of the one resultant password policy that is applied to the user – you do not need to add any additional logic to find the right PSO, as this is what the system has already evaluated in the background.&lt;/p&gt;
&lt;p&gt;Both values only return the DN of the respective PSO =&amp;gt; the PW related attributes of the PSO still need to be read and displayed appropriately to be helpful to the admin/helpdesk folks. &amp;nbsp;This is where I expect the need for a UI to be more important – administrators and helpdesk folks will need a simple UI to show the Resultant-PSO and its values of a user. There is not much magic involved in this task, but one that simply needs to get done. It may be best to simply add a small VB script to the ADUC context menus of a user object via display-specifiers to show these values.&lt;/p&gt;
&lt;p&gt;Note that these attributes are not part of any of the existing permission property sets; by default only members of domain admin group have access to the ms-DS-Resultant-POS attribute and PSO objects – as such this is one more thing to consider when delegating rights for other folks to read (or potentially edit) the password policies.&lt;/p&gt;
&lt;p&gt;All in all I believe this is a very powerful feature - even though not all companies will need it. Especially those that try to get rid of the need of user's typing in their own passwords directly: moving to SmartCards will further increase security and won't require multiple PW policies...&lt;/p&gt;
&lt;p&gt;cheers,&lt;/p&gt;
&lt;p&gt;Guido&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=691301" width="1" height="1"&gt;</description></item><item><title>re: Windows Server 'Longhorn': Granular Password Settings</title><link>http://msmvps.com/blogs/ulfbsimonweidner/archive/2007/03/12/windows-server-quot-longhorn-quot-granular-password-settings.aspx#690821</link><pubDate>Sun, 18 Mar 2007 10:27:28 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:690821</guid><dc:creator>Ulf B. Simon-Weidner</dc:creator><description>&lt;p&gt;Hi Nils,&lt;/p&gt;
&lt;p&gt;while you are right that it would be nice to allow additional settings (grade of complexity, dictionary compares,..) I still believe that this is going in the right direction. What we get for now is less domains for password policy reasons, and a more granular way to decide which users should have which settings when it comes to lockouts and length. This is handy to differenciate regular users, admins, service accounts,...&lt;/p&gt;
&lt;p&gt;If you want to add additional criteria which is not in Windows today at all, you'll have to stick with custom filters - and the risk for doing this. I think a password campaign in your company serves you better than a technical compare to dictionaries. There are enough interfaces out there which you are unable to influence (websites, 3rd-party apps) so your users should get taught what a good password is. Also creating a custom passflt.dll (IMHO) is a technical risk - it could blue-screen your DC since it's pretty deep in the system. Added features (like dictionaries) might increase the risk of a failure, which might leave your DC in a unstable state.&lt;/p&gt;
&lt;p&gt;To answer your question, if you'd still be able to use a custom filter: as far as I know Yes. However if you want the added features described in this post you might need to get a new version of your filters as well, which take these settings into credit.&lt;/p&gt;
&lt;p&gt;Ulf&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=690821" width="1" height="1"&gt;</description></item><item><title>Windows Server Longhorn - Per User Password Policy</title><link>http://msmvps.com/blogs/ulfbsimonweidner/archive/2007/03/12/windows-server-quot-longhorn-quot-granular-password-settings.aspx#685941</link><pubDate>Fri, 16 Mar 2007 16:15:08 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:685941</guid><dc:creator>Musings, Ramblings, and the Occasional Useful Information</dc:creator><description>&lt;P&gt;I can't imagine that this will make the front page of People Magazine , but if you are a Network or Security&lt;/P&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=685941" width="1" height="1"&gt;</description></item><item><title>re: Windows Server 'Longhorn': Granular Password Settings</title><link>http://msmvps.com/blogs/ulfbsimonweidner/archive/2007/03/12/windows-server-quot-longhorn-quot-granular-password-settings.aspx#674726</link><pubDate>Tue, 13 Mar 2007 08:11:47 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:674726</guid><dc:creator>Nils Kaczenski</dc:creator><description>&lt;P&gt;What a pity! To me it seems they just added complexity and missed the chance to add security. Why not implement sophisticated filters that check newly created passwords against a more complete set of criteria - such as dictionaries (a simple yet powerful way to avoid trivial and standard passwords) and all-too-simple variations of common passwords? The filtering functions you describe still allow trash passwords like "aaaaa1!" or the like.&lt;/P&gt;
&lt;P&gt;So we still have to go for common password filters. I hope at least they did not cut the interfaces to do that.&lt;/P&gt;
&lt;P&gt;Somewhat disappointed, Nils&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=674726" width="1" height="1"&gt;</description></item><item><title>Longhorn and password policy</title><link>http://msmvps.com/blogs/ulfbsimonweidner/archive/2007/03/12/windows-server-quot-longhorn-quot-granular-password-settings.aspx#673400</link><pubDate>Mon, 12 Mar 2007 22:31:05 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:673400</guid><dc:creator>Tomek's DS World</dc:creator><description>&lt;p&gt;Ulf (DS MVP) who is now having a lot of fun during MVP summit with other MVPs (I'm really jealous) found&lt;/p&gt;
&lt;img src="http://msmvps.com/aggbug.aspx?PostID=673400" width="1" height="1"&gt;</description></item><item><title>W2K.PL  &amp;raquo; Blog Archive   &amp;raquo; Longhorn i zasady hase??</title><link>http://msmvps.com/blogs/ulfbsimonweidner/archive/2007/03/12/windows-server-quot-longhorn-quot-granular-password-settings.aspx#673379</link><pubDate>Mon, 12 Mar 2007 22:17:01 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:673379</guid><dc:creator>W2K.PL  » Blog Archive   » Longhorn i zasady hase??</dc:creator><description>&lt;p&gt;PingBack from &lt;a rel="nofollow" target="_new" href="http://www.w2k.pl/longhorn-i-zasady-hasel/"&gt;http://www.w2k.pl/longhorn-i-zasady-hasel/&lt;/a&gt;&lt;/p&gt;
&lt;img src="http://msmvps.com/aggbug.aspx?PostID=673379" width="1" height="1"&gt;</description></item></channel></rss>