PDA

View Full Version : 8.5 Remove inactive user accounts at least every 90 days


AtleRiks
06-04-2007, 04:04 AM
I am implementing on linux.

The -I option is used to set the number of days of inactivity after a password has expired before the account is locked. The inactive option is the number of days of inactivity.

If I use INACTIVE=90, it could hypothetically go 180 days before the user account is removed.

Will the server be in compliance?

jbhall56
06-06-2007, 04:17 AM
You want the account disabled or locked at the 90 day mark of inactivity. When you remove the account from the system is up to your security policy on this issue.

I have a number of clients that use seasonal employees, so they do not necessarily remove all locked accounts after the 90 day limit.