Le strategie di sicurezza su Windows NT As estratégias de segurança sob Windows NT Sicherheitsrichtlinien unter Windows NT Les stratégies de sécurité sous Windows NT Directivas de seguridad en Windows NT

Understanding the notion of policy

Security policy is the set of all security rules that are to be implemented in an organisation, and the ways in which they are implemented. The user manager located in the Start Menu (Programs/Administration tools) contains the Policy tag, which includes three elements:

  • Account Policy, with options (check-box or radio buttons) for user connections (options for passwords)
  • User Rights Policy, which defines the permissions granted to each type of user
  • Audit Policy, which defines which events are to be recorded in a log file that can then be viewed with the Event Viewer.

Account Policy

Account Policy is used for selecting password options.

Every account requires a password to access network resources. Some rules are in place to guarantee the best possible security.

  • Assign a password to the Administrator account in order to prevent use of that account by an unauthorised person.
  • Determine who controls passwords. It is possible to assign a unique password to a user or give him or her the capability to change it after logging in for the first time, which allows the user to choose his or her own password.
  • Determine if an account should expire. It is helpful to create temporary accounts for temporary employees.
  • Avoid using obvious passwords (like the name of a parent or a pet)
  • Use a long password (up to 14 characters)
  • Alternate uppercase and lowercase. Passwords are case-sensitive.

Account Policy

The first section of the dialog box is for users' passwords. Passwords are a gateway into the system's security, so it is essential to encourage users to choose passwords that are at least somewhat difficult to guess.

Here are the options offered:

  • Password Restrictions
    • Maximum Password Age defines the length of time that the user may use the password before being required to change it.
    • Minimum Password Age prevents a user from changing the password too often.
    • Minimum Password Length ensures that the password is long enough to stop attempted intrusions.
    • Password Uniqueness: This option keeps a log file of all different passwords used, in order to force the user to choose an entirely new one when needed.
  • Account lockout
    • Lockout duration
    • Determines the number of consecutive failed login attempts before the system blocks the account, and the conditions for unblocking it (a length of time or administrator intervention).
  • The user must change his or her password the next time he or she logs in. The user is also supposed to change the password the first time he or she logs in. This ensures that the user is the only person who knows the password.
  • User cannot change password: If several people use the same user account, or if you want to retain control over passwords.
  • Password never expires: The password may not change. This option has priority over the first.
  • Account deactivated: For temporarily suspending an account.

User Rights Policy

User Rights Policy defines which permissions are granted to each type of user in the system.

Audit Policy

Audit Policy is used to audit certain events (meaning that it records them on the hard drive), or more precisely, to check whether certain system events have succeeded or failed.

Audit Policy appears as a dialog box where an administrator can simply check or uncheck boxes to set the desired policy.

Audit Policy in Windows NT

Last update on Thursday October 16, 2008 02:43:16 PM.This document entitled « Security Policies in Windows NT » from Kioskea (en.kioskea.net) is made available under the Creative Commons license. You can copy, modify copies of this page, under the conditions stipulated by the licence, as this note appears clearly.

Best answers for « Security Policies in Windows NT » in :
Introduction to Windows NT Show Introduction to Microsoft Windows NT Windows NT (for "New Technology") is a 32-bit operating system developed by Microsoft. Windows NT's outward appearance makes it look a lot like Windows 95/98/Millennium, but Windows NT has a separately...
User management in Windows NT Show The notion of a user Windows NT is an operating system which manages sessions, meaning that when the system is started, it is necessary to log in with a user name and password. When Windows NT is installed, the administrator account is created by...
[Windows NT]NT 4.0 SP2+:Enabling the DMA Show [Windows NT]NT 4.0 SP2+:Enabling the DMA Intro Enabling DMA on Windows NT 4.0 SP2 +: Check NT service pack Installation Intro Handling the DMA, for IDE drives is much more difficult under NT4 than under Windows 9x series. Unlike the...
How to disable the security Center under windows XP? ShowHow to disable the security Center under windows XP? Intruduction Disable Alerts Turn off Windows Security Center Intruduction Windows security Center is a component that works under Windows XP service pack 2 for providing...
[Windows XP Home] Add the missing security tab. Show[Windows XP Home] Add the missing security tab Under Windows XP Home Edition, the Security tab is not available for NTFS partitions. First of all check out if indeed it is an NTFS partition. On FAT32 partitions there are no...
Activate Windows XP ShowActivate Windows XP To determine if your version of Windows is activated or windows reminds you to activate the system (normally windows must be activate 30 days after installation). So to activate Windows manually just click on...
Download WinDS PRO ShowWinDS PRO is one of the best emulator for Nintendo DS and Gameboy Advance. This emulator pack will let you play games like Super Mario or Zelda just like you are playing it from the Nintendo Station. Shortcuts: Remove noise. (CTRL +...
Download MBSA ShowMBSA stands for Microsoft Baseline Security Analyzer. This software allows you to analyze your operating system: Windows NT/2000/XP/Server 2003. Once MBSA is launched thrown, you will see: - The red cross indicates that critical updates are...
Sharing and permissions in Windows NT ShowIntroduction to folder sharing Sharing allows resources to be designated as being available to all users over a network. When a folder is shared, users can log into the folder from across the network and access the files within, as though the...
Winlogon - winlogon.exe Showwinlogon - winlogon.exe winlogon.exe (winlogon stands for Windows LogOn Process) is a Windows NT/2000/XP generic process which manages log-on and log-off processes. The process winlogon is also active when the Windows Security window is open (shown...
Explorer - explorer.exe Showexplorer - explorer.exe explorer.exe is a Windows NT/2000/XP generic process. It is a process which manages the user interface (shell) as well as the Windows graphical interface (the desktop). The process explorer is not in any way a virus, a worm,...