You work for a small city IT department and you get a call f

You work for a small city IT department, and you get a call from a user in City Hall who has forgotten her password. What is your response?

A. You locate the list of passwords you have for all employees, find hers, and tell what her password is over the phone.

B. You locate the list of authorized passwords for her department, choose one, go to her computer, and using your administrator password to gain access to her PC, you set her password.

C. You reset the password on her computer to a temporary password, give her the temporary password, and then advise her that she will need to change the password to a permanent password that no one knows.

D. You tell her to look under her keyboard. All employees have their passwords taped under their keyboards for just such an occasion.

Solution

a) You locate the list of passwords you have for all employees, find hers, and tell what her password is over the phone.

Trigger: The administrator provides the account name of the existing account and the new password as input to the client application and invokes the operation that resets the password of an account.

The client application establishes a connection to the directory server. Windows Authentication Services uses the supplied credentials to authenticate the client application ([MS-AUTHSOD] section 2).

The client application sends a request to the directory server to reset the password of an existing account. This request includes the account name of the account and the new password supplied by the administrator.

The directory server verifies that the credentials that are supplied through the client application have the necessary access-control rights to complete the operation. ([MS-ADTS] section 5.1.3).

The directory server verifies that the new password satisfies the password policy, as described in [MS-SAMR] section 3.1.1.7.1.

The directory server updates the password of the existing account with the new value that is supplied in the request. Additional attributes are updated as mandated by the server\'s processing rules and constraints ([MS-ADTS] sections 3.1.1.5.1 and 3.1.1.5.3 and [MS-SAMR] section 3.1.1.8.7).

The directory server sends a response to the client application that the password has been successfully updated.

You work for a small city IT department, and you get a call from a user in City Hall who has forgotten her password. What is your response? A. You locate the li

Get Help Now

Submit a Take Down Notice

Tutor
Tutor: Dr Jack
Most rated tutor on our site