heroui logo

ZIA Password Expiration

Panther Rules

View Source
Summary
The ZIA Password Expiration rule is designed to detect changes in password expiration settings within the Zscaler Internet Access (ZIA) platform. This rule triggers an alert when a change is made to either enable or disable password expiration features for user accounts. With the ability to set password expiration policies, organizations can ensure compliance with security best practices regarding user authentication. This rule is especially critical as it oversees password lifecycle management, ensuring that user credentials are periodically updated, thereby reducing the risk of unauthorized access due to stale passwords. The logging mechanisms track administrative actions related to password expiration and provide a record of changes, including who made them and from which IP address. The rule aims to monitor these alterations and can bring a response team into action if unexpected modifications are detected. In essence, it acts as a safeguard allowing administrators to maintain security policies in line with organizational requirements.
Categories
  • Cloud
  • Identity Management
  • Web
Data Sources
  • User Account
  • Application Log
ATT&CK Techniques
  • T1201
Created: 2024-11-06