Accounts Using Old Passwords

medium

Description

To mitigate the risk of credential theft, the passwords of all active accounts in Active Directory, including computer accounts, should be renewed regularly. However, if users must change their passwords too frequently, this may lead to the selection of predictable passwords or the storage of passwords in unsafe locations, increasing the likelihood of credential theft.

Solution

Tenable recommends implementing a password renewal policy for accounts with sensitive access rights in the information system. Configure this policy to prevent users from changing their password too frequently, which could increase the likelihood of predictable password use.

See Also

NIST SP 800-63-4 - Digital Identity Guidelines

Security baseline (FINAL) for Windows 10 v1903 and Windows Server v1903

NCSC - Password administration for system owners

Domain member: Maximum machine account password age

Indicator Details

Name: Accounts Using Old Passwords

Codename: C-USER-PASSWORD

Severity: Medium

Type: Active Directory Indicator of Exposure

Family: Authentication and Credentials

MITRE ATT&CK Information:

Attacker Known Tools

van Hauser / THC: THC-Hydra

Solar Designer: John the Ripper

Jens Steube: Hashcat