Quantcast
Channel: Group Policy forum
Viewing all articles
Browse latest Browse all 19997

Server 2008R2: Can Password Complexity Rules be used against Smart Card PIN changes

$
0
0

Scenario:

A user is logged in with a smart card (actually, a US government PIV card). We are concerned about the Ctrl-Alt-Del password change dialog where a PIN (password) can be changed. Our policies dictate the following requirements on the PIN:

1. Length 6 to 8 bytes.

2. Digits only.

3. Deny things like 0000000 or 11111111.

I believe this validation cannot be done in this dialog; that the complexity rules work with "real" passwords only.  Please, correct me if I'm wrong. I'd like to hear any other solutions you may have.


Viewing all articles
Browse latest Browse all 19997

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>