Use a proper inband/outband setup and RDP is just fine, but yes, for every day admin built in remote tools should be used.- wherever possible don't RDP onto a Windows server.
rotate passwords frequently.
Which passwords? CESG actually recommend that passwords aren't rotated/expired now.
https://www.cesg.gov.uk/articles/problems-forcing-regular-password-expiry
Out of interest, have you got a source or standard that backs that statement up?Admin passwords should be rotated regularly, ideally after every session...
Out of interest, have you got a source or standard that backs that statement up?
Can't say i've heard of that before and would assume that's impractically in a lot of situations.
Out of interest, have you got a source or standard that backs that statement up?
Can't say i've heard of that before and would assume that's impractically in a lot of situations.
As mentioned above there are tools that do this.
I worked somewhere whereby admin credentials were checked out when you wanted to use them (and needed two people to put in their halves of the password that allowed you to do so), then when you logged out it changed the password with a new one it had generated.
How secure is the mechanism that's resetting the admin password?
Either way it seems a bit extreme, you don't need the password, you just need a user account capable of resetting the password (EoP)
Either way it seems a bit extreme![]()
Depends what it is you are protecting...
You don't need to lock them passwords up so secure (other than to appease auditors) because at the end of the day bypassing them or resetting them is far simpler.
I found that those methods work on 2012, but not on 2012 R2.