Password never expires |
---|
Risk Level: | Low | Check or Attack Name: Password Never Expires |
---|---|---|
Platforms: | Windows NT | |
Description: | The user has a password that will never expire. Unless the user is used for a service account and has a very strong password, this setting will lower your security level, as an attacker has an unlimited amount of time to guess the password, and an unlimited amount of time to use the password once it is guessed. |
|
Remedy: | Remove the Password Never Expires option:
|
|
References: |
Know Your Risks |