Ireda
Sep 12, 2023Cirrostratus
APM Password policy
Dears We need to enable the password policy on IT-Admin accounts as per the below details, Is the below ok, or what is recommended? Is there any impact?
1- how can I send expiration notifications?
I personally don't use expiration notifications, i use the f5 to enforce a password update.
You can do this on the day or give them a certain amount of days to bypass the password change before its enforced. The only thing being is that i do this with AD (its controlled using the AD Query) i don't know if that functionality is avaiable when using the local user database. JRahm is there someone who can answer this?
Getting the f5 to manage the change is quick, and ensures its done and people don't miss notificaitions before the account is locked.
2- If the user did not see the notification, the expiration period is finished and the user is locked, how user can change the password?
Using a password update feature may be best for you here, as long as they know their previous password it should work nicely for you.
3- if the user is locked, is another admin can unlock this user? if yes, is the user must change the password after unlock, or maybe user's last password?
I've done this using AD, so clicking the box in the user on AD for "user changes password at next logon" triggers the f5 to enforce a password update. Very nice and clean. If its using the internal user DB i don't know hopefully Jason can find someone for you to help.
Hope this helps.
Dears,
Please support us in below:
I'm not sure how to do the expiration warning, as your using internal auth.
But what ever happens your root and admin access will still be in place so you can always get in to fix an account.