Maximum password age incorrect

Risk Level: Low risk vulnerability  Low

Check or Attack Name: Max Pwd Age

Platforms: Windows NT
Description:

The maximum password age is longer than your policy specifies. Passwords should be changed on a regular basis.

Remedy:

Set the maximum password age value so that it equals or is less than the value in the current policy. A value of 30 to 42 days is recommended.

To configure the password age, follow these steps:

  1. Open User Manager. From the Windows NT Start menu, select Programs, Administrative Tools (Common), User Manager.
  2. From the Policies menu, select Account to display the Account Policy dialog box.
  3. In the Maximum Password Age box, set the Allow Changes In value to at most the value specified by the current policy.
  4. Click OK.
References:

Microsoft Knowledge-Pak Network Suite 10141569, How to: Set maximum password age policy., http://support.microsoft.com/support/ntserver/serviceware/10141569.asp


X-Force Logo
Know Your Risks