I perform log monitoring for a large subset of servers at $MEGACORP. One of the events I monitor is event id 627, the account password change attempt. I set the threshold at 12 attempts per day, because our policies state that you need to change your password frequently, not use the same password in the 6 month period, and not use any of the last
(
Read more... )