๐ŸชŸPassword Policies (from Windows)

Enumerating & Retrieving Password Policies

net.exe

๐Ÿ”ณnet.exechevron-right

Code

net accounts

Example

Force user logoff how long after time expires?:       Never
Minimum password age (days):                          1
Maximum password age (days):                          Unlimited
Minimum password length:                              8
Length of password history maintained:                24
Lockout threshold:                                    5
Lockout duration (minutes):                           30
Lockout observation window (minutes):                 30
Computer role:                                        SERVER
The command completed successfully.

PowerView

๐Ÿ”ญPowerViewchevron-right

Code

Example

Additional Info:

  • It also revealed that password complexity is enabled (PasswordComplexity=1)

Analyzing the Password Policy

  • The minimum password length

  • The account lockout threshold

  • The lockout duration

  • Accounts unlock automatically or requires administrator's intervention

  • Password complexity is enabled, meaning that a user must choose a password with 3/4 of the following: an uppercase letter, lowercase letter, number, special character

Default Password Policy

Policy
Default Value

Enforce password history

24 days

Maximum password age

42 days

Minimum password age

1 day

Minimum password length

7

Password must meet complexity requirements

Enabled

Store passwords using reversible encryption

Disabled

Account lockout duration

Not set

Account lockout threshold

0

Reset account lockout counter after

Not set

Last updated