4 ms·
How are you implementing these checks? I'm using Active Directory and options for extra password checks are somewhat limited.
by omh 7y ago
How are you implementing these checks?
I'm using Active Directory and options for extra password checks are somewhat limited.
- LeoPanthera 7y agoOh sorry I'm not using AD, it's just a web service.
- technion 7y agoMicrosoft has a pwnedpasswords-like service you can use: https://docs.microsoft.com/en-us/azure/active-directory/authentication/concept-password-ban-bad-on-premises https://docs.microsoft.com/en-us/azure/active-directory/auth...
- discreditable 7y ago* If you use Azure Active Directory
- funnybeam 7y agoOn-premises AD has the same functionality but it is a pain to set up and so limited as to be not worth the effort
- omh 7y agoI don't think this (Azure AD Password Protection) actually implements a pwnedpasswords-style check. It lets you upload your own custom list of banned passwords but it's limited to 1000 words. My impression is that this is intended to blacklist common words and things like your company name. I see that Troy Hunt is now working for Microsoft so perhaps there's something in the works related to this. It seems like linking this Azure AD service to the haveibeenpwned API would be pretty straightforward.
- asimops 7y agoYou can use a dll to do additional security checks on a domain controller base. Check this https://github.com/JacksonVD/PwnedPasswordsDLL-API https://github.com/JacksonVD/PwnedPasswordsDLL-API
- discreditable 7y agoThe problem is the password change UI on Windows systems is terrible. It does not give users any clue why their password was not accepted other than "Unable to update the password. The value provided does not meet the length, complexity, or history requirements of the domain."
- shakna 7y agoIf you have the DS-Replication-Get-Changes permission, you can exploit dc-sync through something like mimikatz [0] to grab the password hashes out of Active Directory, so you can run your checks. [0] https://github.com/gentilkiwi/mimikatz https://github.com/gentilkiwi/mimikatz