Enable reversible encryption for a specific user.

Enable reversible encryption for a specific user.

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Enable reversible encryption for a specific user. study 06-24-2008
Posted by =?Utf-8?B?c3R1ZHk=?= on June 24, 2008, 1:19 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
The default domain policy's password policy has "enable reversible encrypted
password" disabled and since there can be only one account policy per domain,
this one takes precedence right?

I found this though "To enable reversibly encrypted passwords for a specific
user you can modify their User Properties -> Account options -> enable Store
Password using Reversible Encryption. You must then reset their password."
Does this work? I thought that the defaul domain policy's password policy
always takes precedence and will win if there's a conflict with another
setting such as this.

Thanks.

Posted by Steve Riley [MSFT] on June 24, 2008, 11:30 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Yes, you can enable this on a per-user basis as you describe.

What requires you to do this? Just curious...


--
Steve Riley
steve.riley@microsoft.com
http://blogs.technet.com/steriley
http://www.protectyourwindowsnetwork.com



> The default domain policy's password policy has "enable reversible
> encrypted
> password" disabled and since there can be only one account policy per
> domain,
> this one takes precedence right?
>
> I found this though "To enable reversibly encrypted passwords for a
> specific
> user you can modify their User Properties -> Account options -> enable
> Store
> Password using Reversible Encryption. You must then reset their password."
> Does this work? I thought that the defaul domain policy's password policy
> always takes precedence and will win if there's a conflict with another
> setting such as this.
>
> Thanks.


Posted by =?Utf-8?B?c3R1ZHk=?= on June 25, 2008, 12:34 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Thanks. Some legacy application needs it...
Since kerberos settings ex) Maximum lifetime for service ticket, Maximum
lifetime for user ticket renewal, and Maximum tolerance for computer clock
synchronization are part of the account policy, there can only be one
kerberos settings per domain right (usually set at the default domain policy)?


"Steve Riley [MSFT]" wrote:

> Yes, you can enable this on a per-user basis as you describe.
>
> What requires you to do this? Just curious...
>
>
> --
> Steve Riley
> steve.riley@microsoft.com
> http://blogs.technet.com/steriley
> http://www.protectyourwindowsnetwork.com
>
>
>
> > The default domain policy's password policy has "enable reversible
> > encrypted
> > password" disabled and since there can be only one account policy per
> > domain,
> > this one takes precedence right?
> >
> > I found this though "To enable reversibly encrypted passwords for a
> > specific
> > user you can modify their User Properties -> Account options -> enable
> > Store
> > Password using Reversible Encryption. You must then reset their password."
> > Does this work? I thought that the defaul domain policy's password policy
> > always takes precedence and will win if there's a conflict with another
> > setting such as this.
> >
> > Thanks.
>

Posted by Steve Riley [MSFT] on June 25, 2008, 6:41 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
The reversible encryption setting has nothing to do with Kerberos. You can
keep your domain policy at the default and enable per-user reversible
encryption on individual accounts.

--
Steve Riley
steve.riley@microsoft.com
http://blogs.technet.com/steriley
http://www.protectyourwindowsnetwork.com



> Thanks. Some legacy application needs it...
> Since kerberos settings ex) Maximum lifetime for service ticket, Maximum
> lifetime for user ticket renewal, and Maximum tolerance for computer clock
> synchronization are part of the account policy, there can only be one
> kerberos settings per domain right (usually set at the default domain
> policy)?
>
>
> "Steve Riley [MSFT]" wrote:
>
>> Yes, you can enable this on a per-user basis as you describe.
>>
>> What requires you to do this? Just curious...
>>
>>
>> --
>> Steve Riley
>> steve.riley@microsoft.com
>> http://blogs.technet.com/steriley
>> http://www.protectyourwindowsnetwork.com
>>
>>
>>
>> > The default domain policy's password policy has "enable reversible
>> > encrypted
>> > password" disabled and since there can be only one account policy per
>> > domain,
>> > this one takes precedence right?
>> >
>> > I found this though "To enable reversibly encrypted passwords for a
>> > specific
>> > user you can modify their User Properties -> Account options -> enable
>> > Store
>> > Password using Reversible Encryption. You must then reset their
>> > password."
>> > Does this work? I thought that the defaul domain policy's password
>> > policy
>> > always takes precedence and will win if there's a conflict with another
>> > setting such as this.
>> >
>> > Thanks.
>>

Posted by =?Utf-8?B?c3R1ZHk=?= on June 25, 2008, 8:28 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
I was asking whether kerberos settings were per domain based (one policy per
domain) as well...


"Steve Riley [MSFT]" wrote:

> The reversible encryption setting has nothing to do with Kerberos. You can
> keep your domain policy at the default and enable per-user reversible
> encryption on individual accounts.
>
> --
> Steve Riley
> steve.riley@microsoft.com
> http://blogs.technet.com/steriley
> http://www.protectyourwindowsnetwork.com
>
>
>
> > Thanks. Some legacy application needs it...
> > Since kerberos settings ex) Maximum lifetime for service ticket, Maximum
> > lifetime for user ticket renewal, and Maximum tolerance for computer clock
> > synchronization are part of the account policy, there can only be one
> > kerberos settings per domain right (usually set at the default domain
> > policy)?
> >
> >
> > "Steve Riley [MSFT]" wrote:
> >
> >> Yes, you can enable this on a per-user basis as you describe.
> >>
> >> What requires you to do this? Just curious...
> >>
> >>
> >> --
> >> Steve Riley
> >> steve.riley@microsoft.com
> >> http://blogs.technet.com/steriley
> >> http://www.protectyourwindowsnetwork.com
> >>
> >>
> >>
> >> > The default domain policy's password policy has "enable reversible
> >> > encrypted
> >> > password" disabled and since there can be only one account policy per
> >> > domain,
> >> > this one takes precedence right?
> >> >
> >> > I found this though "To enable reversibly encrypted passwords for a
> >> > specific
> >> > user you can modify their User Properties -> Account options -> enable
> >> > Store
> >> > Password using Reversible Encryption. You must then reset their
> >> > password."
> >> > Does this work? I thought that the defaul domain policy's password
> >> > policy
> >> > always takes precedence and will win if there's a conflict with another
> >> > setting such as this.
> >> >
> >> > Thanks.
> >>

Similar ThreadsPosted
Locking out a specific user from a specific client April 28, 2007, 1:47 pm
Specific user NTFS permission August 14, 2006, 7:43 am
Cant add (specific) Printer with user account January 8, 2007, 5:41 am
grant an user the ability to enable/disable account April 5, 2006, 3:21 pm
PKI email encryption varies from user to user October 18, 2006, 2:09 pm
Access to a specific IP for only 2 users May 14, 2007, 6:11 am
Should I enable TLS 1.0? October 27, 2006, 7:38 pm
Check if specific updates are installed June 19, 2005, 7:16 pm
platform specific attractiveness of targets December 7, 2005, 12:43 pm
scripting specific folder permissions August 9, 2006, 8:33 am

The site map in XML format XML site map

Contact Us | Privacy Policy