HEX
Server: Apache/2.4.46 (Win64) OpenSSL/1.1.1j PHP/8.4.25
System: Windows NT DESKTOP-4TAV2RJ 10.0 build 19045 (Windows 10) AMD64
User: fred (0)
PHP: 8.4.25
Disabled: NONE
Upload Files
File: C:/Windows/PolicyDefinitions/zh-TW/LAPS.adml
<policyDefinitionResources revision="1.0" schemaVersion="1.0">
  <displayName>
  </displayName>
  <description>
  </description>
  <resources>
    <stringTable>
      <string id="LAPS">區域系統管理員密碼解決方案 (LAPS)</string>
      <string id="LAPS_BackupDirectory">設定密碼備份目錄</string>
      <string id="LAPS_BackupDirectory_Help">使用此設定來設定要備份本機系統管理員帳戶密碼的目錄。

允許的設定為:

 0=停用 (將不會備份密碼)

 1=備份密碼以 Azure Active Directory 

 2=備份密碼以 Active Directory

若未指定,此設定將預設為 0 (停用)。

如果此設定設定為 1,且受管理的裝置未加入 Azure Active Directory,則不會管理本機系統管理員密碼。

如果此設定設定為 2,且受管理的裝置未加入 Active Directory,則不會管理本機系統管理員密碼。

如果停用或未設定這個設定,則不會管理本機系統管理員密碼。

如需詳細資訊,請參閱 https://go.microsoft.com/fwlink/?linkid=2188435。
      </string>
      <string id="LAPS_BackupDirectoryDisabled">已停用</string>
      <string id="LAPS_BackupDirectoryAzure">Azure Active Directory</string>
      <string id="LAPS_BackupDirectoryAD">Active Directory</string>
      <string id="LAPS_PasswordSettings">密碼設定</string>
      <string id="LAPS_PasswordSettings_Help">設定密碼參數

密碼複雜性: 產生新密碼時會使用哪些字元
  預設值: 大寫字母 + 小寫字母 + 數位 + 特殊字元

密碼長度
  最少: 8 個字元
  最大值: 64 個字元
  預設值: 14 個字元

密碼使用期限天數
  最小值: 將備份目錄設定為 Azure AD) 1 天 (7 天
  最大值: 365 天
  預設值: 30 天

如需詳細資訊,請參閱https://go.microsoft.com/fwlink/?linkid=2188435。
      </string>
      <string id="LAPS_PwdComplexity_Item_1">大寫字母</string>
      <string id="LAPS_PwdComplexity_Item_2">大寫字母 + 小寫字母</string>
      <string id="LAPS_PwdComplexity_Item_3">大寫字母 + 小寫字母 + 數字</string>
      <string id="LAPS_PwdComplexity_Item_4">大寫字母 + 小寫字母 + 數字 + 特殊符號</string>
      <string id="LAPS_AdminName">要管理的系統管理員帳戶名稱</string>
      <string id="LAPS_AdminName_Help">這個原則設定指定要管理密碼的自訂系統管理員帳戶名稱。

如果啟用此原則設定,LAPS 將會使用此名稱管理本機帳戶的密碼。

如果停用或未設定這個原則設定,LAPS 將會管理已知系統管理員帳戶的密碼。

請勿啟用此原則設定以管理內建系統管理員帳戶。已知 SID 會自動偵測內建的系統管理員帳戶,且不依存于帳戶名稱。

如需詳細資訊,請參閱https://go.microsoft.com/fwlink/?linkid=2188435。
      </string>
      <string id="LAPS_DontAllowPwdExpirationBehindPolicy">不允許密碼到期時間超過原則要求的時間</string>
      <string id="LAPS_DontAllowPwdExpirationBehindPolicy_Help">如果啟用或未設定此設定,則不允許計畫的密碼到期時間超過「密碼設定」原則所指定的密碼期限。偵測到這種到期日時,會立即變更密碼,並根據原則設定密碼到期。

如果停用此設定,密碼到期時間可能會比「密碼設定」原則要求的時間長。

如需詳細資訊,請參閱https://go.microsoft.com/fwlink/?linkid=2188435。
      </string>
      <string id="LAPS_ADPasswordEncryptionEnabled">啟動密碼加密</string>
      <string id="LAPS_ADPasswordEncryptionEnabled_Help">當您啟用此設定時,受管理的密碼會先加密,再傳送到 Active Directory。

啟用此設定不會有作用,除非已將 1)密碼設定為備份到 Active Directory,2) Active Directory 網域功能等級為 Windows Server 2016 或以上。

如果啟用此設定,且網域功能等級在或高於 Windows Server 2016,則會加密受管理帳戶密碼。

如果啟用此設定,且網域功能等級小於 Windows Server 2016,則受管理帳戶密碼不會備份到目錄。

如果停用此設定,則不會加密受管理的帳戶密碼。

若未設定,此設定會預設為啟用。

如需詳細資訊,請參閱https://go.microsoft.com/fwlink/?linkid=2188435。
      </string>
      <string id="LAPS_ADPasswordEncryptionPrincipal">設定授權的密碼解密程式</string>
      <string id="LAPS_ADPasswordEncryptionPrincipal_Help">設定此設定以控制授權解密加密密碼的特定使用者或群組。

除非啟用密碼加密,否則設定此設定不會有作用。

如果啟用此設定,指定的群組將解密加密的密碼。

如果停用或未設定此設定,則網域系統管理員群組將可解密加密的密碼。

此設定必須使用字串格式 (「S-1-5-21-2127521184-1604012920-1887927527-35197」)的 SID,或是使用「網域\(群組或使用者)」 格式的群組或使用者名稱。指定的使用者或群組必須可由受管理的裝置解析,否則將不會備份密碼。

如需詳細資訊,請參閱 https://go.microsoft.com/fwlink/?linkid=2188435。
      </string>
      <string id="LAPS_ADEncryptedPasswordHistorySize">設定加密密碼歷程記錄的大小</string>
      <string id="LAPS_ADEncryptedPasswordHistorySize_Help">使用此設定來設定先前儲存在 Active Directory 中的加密密碼數目。

除非已將 1) 密碼設定為備份至 Active Directory,而且 2) 已啟用密碼加密,否則設定此設定不會有作用。

如果啟用此設定,指定的舊密碼數目將會儲存在 Active Directory 中。

如果停用或未設定這個設定,則不會將舊密碼儲存在 Active Directory 中。

此設定的允許值下限為 0 個密碼。

此設定允許的值上限為 12 個密碼。

如需詳細資訊,請參閱 https://go.microsoft.com/fwlink/?linkid=2188435。
      </string>
      <string id="LAPS_ADBackupDSRMPassword">啟用 DSRM 帳戶的密碼備份</string>
      <string id="LAPS_ADBackupDSRMPassword_Help">當您啟用此設定時,DSRM 系統管理員帳戶密碼將會受管理並備份到 Active Directory。

除非受管理的裝置是網域控制站,而且也已啟用密碼加密,否則啟用此設定不會生效。

如果啟用此設定,網域控制站上之 DSRM 系統管理員帳戶的密碼將備份至 Active Directory。

如果停用或未設定此設定,網域控制站上 DSRM 系統管理員帳戶的密碼將不會備份到 Active Directory。

如需詳細資訊,請參閱 https://go.microsoft.com/fwlink/?linkid=2188435。
      </string>
      <string id="LAPS_PostAuthenticationActions">驗證後動作</string>
      <string id="LAPS_PostAuthenticationActions_Help">此原則會設定在偵測到受管理帳戶的驗證之後,將會執行的驗證後動作。

寬限期: 指定在執行指定的驗證後動作之前,驗證後等待的時間 (小時)。

如果啟用此設定且大於零,則會在寬限期到期時執行指定的驗證後動作。

如果停用或未設定此設定,則會在預設的 24 小時寬限期之後執行指定的驗證後動作。

如果此設定等於零,則不會執行驗證後動作。

動作: 指定寬限期到期時要採取的動作。

重設密碼: 寬限期到期時,會重設受管理帳戶密碼。

重設密碼並登出受管理帳戶: 寬限期到期時,將重設受管理帳戶密碼,並終止任何使用受管理帳戶的互動式登入工作階段。

(注意: 終止任何互動式登入工作階段之後,受管理帳戶可能仍有其他已驗證的工作階段在使用中。確保以前的密碼使用時間更長的唯一可靠方法是重新啟動裝置。)

重設密碼並重新啟動: 寬限期到期時,將重設受管理帳戶密碼,且會立即重新啟動受管理的裝置。

如果停用或未設定此設定,驗證後動作將預設為「重設密碼並登出受管理的帳戶」。

注意: 無法為驗證後動作設定網域控制站上的 DSRM 帳戶。此原則對網域控制站沒有作用,即使為 DC 設定也會被略過。

如需詳細資訊,請參閱https://go.microsoft.com/fwlink/?linkid=2188435。
      </string>
      <string id="PostAuthenticationActions_Item0">已停用 - 不採取任何動作</string>
      <string id="PostAuthenticationActions_Item1">重設密碼</string>
      <string id="PostAuthenticationActions_Item3">重設密碼並登出受管理帳戶</string>
      <string id="PostAuthenticationActions_Item5">重設密碼並將重新啟動裝置</string>
      <string id="SUPPORTED_Windows10">至少為 Microsoft Windows 10 或更新版本</string>
    </stringTable>
    <presentationTable>
      <presentation id="LAPS_BackupDirectory">
        <dropdownList refId="LAPS_BackupDirectory" defaultItem="1">備份目錄</dropdownList>
      </presentation>
      <presentation id="LAPS_PasswordSettings">
        <dropdownList refId="LAPS_PasswordComplexity" defaultItem="3">密碼複雜性</dropdownList>
        <decimalTextBox refId="LAPS_PasswordLength" defaultValue="14">密碼長度</decimalTextBox>
        <decimalTextBox refId="LAPS_PasswordAgeDays" defaultValue="30">密碼使用期限 (天)</decimalTextBox>
      </presentation>
      <presentation id="LAPS_AdminName">
        <textBox refId="TEXT_AdminAccountName">
          <label>系統管理員帳戶名稱</label>
        </textBox>
      </presentation>
      <presentation id="LAPS_ADPasswordEncryptionPrincipal">
        <textBox refId="TEXT_ADPasswordEncryptionPrincipal">
          <label>授權的密碼解密程式</label>
        </textBox>
      </presentation>
      <presentation id="LAPS_ADEncryptedPasswordHistorySize">
        <decimalTextBox refId="LAPS_ADEncryptedPasswordHistorySize_INT" defaultValue="0">加密的密碼歷程記錄大小</decimalTextBox>
      </presentation>
      <presentation id="LAPS_PostAuthenticationActions">
        <decimalTextBox refId="LAPS_PostAuthenticationResetDelay_INT" defaultValue="24">寬限期 (小時):</decimalTextBox>
        <dropdownList refId="LAPS_PostAuthenticationActions" defaultItem="3">動作:</dropdownList>
      </presentation>
    </presentationTable>
  </resources>
</policyDefinitionResources>