Windows XP to improve account password security

  
                

Most users know how to set an account password for the WinXP system, but the level of the password is absolutely normal. There is a way for Xiaobian to now, without the need for third-party software, just a few clicks of the mouse and enter a few values ​​to improve the security of the password.

We usually define a more secure password rules used in the system of the & ldquo; Local Security Settings & rdquo; tools, can & ldquo; start & rarr; run & rdquo; Enter & ldquo; secpol.msc & rdquo; Activate it. In the tree on the left side of the main window, expand "Account Policies & Rarr; Password Policy". The password rules we want to define are the options displayed in the right panel!

Setting Password Complexity

First double-click "The password must meet the complexity requirement", set the security setting to "Allowed", and the password created by the user in the "Control Panel → User Account" must contain the case. English, Arabic numerals and special characters, three types of characters, if one of the characters is not included, a dialog box will pop up.

Minimum password length: The minimum number of digits a user can create a password. You can enter an Arabic number between 0 and 14. 0 means that the password length created is not required to be detected. Once the password created by the user does not meet the required number of digits, the system will also pop up a dialog box warning.

Maximum password retention period: This option is more interesting. It is the expiration time of setting the password, that is, the new password that meets the requirements must be replaced within the specified period. Of course, setting it to 0 means that the password is never invalid, and the longest cycle time is 999 days.

The minimum password retention period: as opposed to the “Maximum password retention period” option, which is the minimum time to set the password to survive. During this time, the user is not allowed to change the password. Similarly, set to 0 to change the password at any time, the maximum time a password can survive is 998 days.

Enforce password history: Change passwords frequently, it will inevitably generate multiple different passwords, and the system will help you  memory the password you have used, the number of passwords you can remember is up to you Come “ tell & rdquo; system. 0 means no password reservation history, the system can only help you remember 24 password history, the original system memory is also limited.

Use a recoverable encryption for all users in the domain to store passwords: To keep your password secure, we recommend disabling this feature.

Clearly the specific meaning and scope of each option, we can flexibly customize the password rules, the author here provides a reference scheme: password complexity requirements enable, password length minimum set to 8 characters, mandatory password After the history is set to 0, the longest (short) retention period of the password is determined. Generally, the longest retention period is set to 2 to 3 times of the minimum retention period. If the maximum retention period is set to 30 days, the minimum retention period can be set. For 10 days, this is more reasonable.

Renaming the System Administrator Account

The WinXP default system administrator account name is "Administrator" (the so-called real system administrator account), many system experts recommend users This account is password-set because the account is hidden under normal system status, and in the security mode, the account resolutely appears in the login screen. In the case where no password is set, of course, no password can be used. Into the system. In the “Local Security Settings”, we can rename the system administrator account name, expand ““local policy →security options” in the left tree, double click on the right panel Account: Rename System Management Administrator Account”, in the pop-up window, you can enter a new system administrator account. However, after several tests, the new system administrator account name cannot be the name of the currently logged in administrator account, otherwise the “Failed to save local policy database” error dialog box pops up.

In fact, when you install WinXP system, the created account nickname is not allowed to be the Administrator and Guest name. If you want to use the same account nickname, you don't have to enter any account nickname in this account. Characters, directly cold start system, after restarting, WinXP has skipped the account nickname step and directly logs in to the system as an Administrator account.

The above is a small list of ways to enhance password security. Friends and friends in the process of operation, if there are any problems, welcome to interact with Xiaobian message.

Copyright © Windows knowledge All Rights Reserved