User credentials

IT_RACK5500 21 Reputation points
2021-07-31T14:58:41.367+00:00

Hi,

We have always been going with static password and never changed a user's password. I know this is one of the most wrong and dangerous practice but this is how the management wanted it to be. Now we got the go ahead to change the password every 2 months.

We also keep the passwords for all the users so that we can log in as the user when need be to troubleshoot.

My questions are as follows:

(1)If we allow the user to change the password, how can we log in as the user to trouble shoot?

(2)Is it legal to keep the users credentials ?

Just wanted to add that we are using Exchange

Thanks

Tazio

Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,425 questions
{count} votes

Accepted answer
  1. Andy David - MVP 143.3K Reputation points MVP
    2021-07-31T17:41:22.213+00:00

    Not ever changing a user's password is not an issue. And changing the password every two months doesn't protect you.
    Not using multi-factor authentication is a problem and should be where your focus should be:

    https://learn.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-getstarted

    If you aren't using Azure, consider a hybrid solution with Azure or a third party solution

    This isnt really an Exchange issue however.

    There is absolutely no reason to keep any user credentials. Has nothing to do with legality, there is simply no reason to do this.
    If you need to troubleshoot a users mailbox, an admin can give yourself permission to it:

    https://support.microsoft.com/en-us/topic/how-to-grant-exchange-and-outlook-mailbox-permissions-in-office-365-dedicated-bac01b2c-08ff-2eac-e1c8-6dd01cf77287#bkmk_1

    Personally, I would never work for a company that required me to provide my password to them.

    1 person found this answer helpful.
    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. IT_RACK5500 21 Reputation points
    2021-08-10T18:55:08.267+00:00

    Thanks a lot for your answers

    Tazio

    0 comments No comments