PCI DSS compliance Password requirements
Good day, by mistake I posted this question on the wrong forum.. http://social.answers.microsoft.com/Forums/en-US/w7security/thread/d3f60946-e87a-461e-a603-2e68d21013eb anyway, I am a windows Administrator on a small Domain in a bank. 2 Roots and 9 children. and I have a requirement from our Security department to enable the password complexity on the group policy for the users. however, since we are using so many applications, the users already have a good number of passwords to remember and don't want to put a complex addition to them. so, they asked if it is possible to force the password to be alphanumeric only (letters + digits), no need for special caracthers nor caps or smalls. Microsoft Windows 2003 has the Complexity option, but if enabled then it must meet 3 categories mentioned in this article http://msdn.microsoft.com/en-us/library/ms161959.aspx so, is it possible to have a password enable with minimum alphanumeric and not what mentioned in the article above? Regards, Rizaey
January 5th, 2010 8:40pm

Not without creating your own password filter, which requires programming. Details can be found on the MSDN web site. Or there are 3rd parties that sell custom password filters. You should be able to find them by searching the web. Paul Adare CTO IdentIT Inc. ILM MVP
Free Windows Admin Tool Kit Click here and download it now
January 5th, 2010 10:12pm

thank you for the answer. that is what I need to provide to Security Department ;). I will check the MSDN as well. as for the 3rd parties. I will try to find one, however it will be costly for nothing. This PCI request is some kind non-sense. I personally believe, a password either a complex or not. not only lower case alphanumeric! cheers and thanks.
January 5th, 2010 11:09pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics