Windows Integrated Authentication: How does SPSS Statistics Server handle expired user credentials?
0 reputation · 27 Dec 2020, 04:11 UTC
0 reputation · 27 Dec 2020, 04:11 UTC
SPSS Statistics Server can be configured to use Windows Integrated Authentication, delegating access control to the Windows domain. The server itself does not enforce a least‑privilege model beyond what the domain defines.
When a Windows user’s password expires, the server typically accepts the login attempt, but the underlying Windows authentication process may reject the session or prompt the user to change the password, depending on domain policy and SPSS configuration. No documented SPSS feature automatically revokes or denies access for expired credentials.
It remains unclear whether SPSS Statistics Server should provide its own mechanism to detect and block access for accounts with expired passwords, independent of Windows, to enforce least‑privilege more strictly. Implementing such a mechanism would require integration with Windows authentication events or querying the domain controller before authorizing a session.
Given this uncertainty, the following questions arise:
A thoughtful contribution can make all the difference. Be the first to share one.
Use comments to ask for clarification. Post a solution as an answer.
No question comments on this page.