How do I programatically dissable a user account?

I'm writing an application that needs to be 21 CFR Part 11 compliant, and this would be an effective loss management procedure for lost/stolen usernames and passwords.  I'm using the DSC 8.2.1 module and can see no way to do this other than through the Domain Account Manager by the administrator.  I would like my application program to be able to dissable an account after a number of failed login attempts.  Since this used to be a feature of earlier versions of the DSC module, I don't understand why NI took it out of later versions.
Thanks,
Craig

Hi, Austin,
Thanks for the reply.  Yes, I have read through the Developer Zone tutorial many times, and have been using it as a reference.  I posted a question a couple of months ago that you replied to about how to set minutes idle until logoff and number of failed login attempts.  I was able to implement an automatic logout feature after a number of minutes of inactivity in the application just fine.  However, in the very last part of the article, it says this:
(c) Following loss management procedures to electronically deauthorize lost, stolen, missing, or otherwise potentially compromised tokens, cards or password information, and to issue temporary or permanent replacements using suitable, rigorous controls.
Although it is ultimately the responsibility of the developer to implement procedures to ensure that this regulation is met, the DSC module provides you with some tools to help. The locking out of user names that fail consecutive logins can help to identify a compromised user name. Also, the administrator can deactivate any user name and can add a new temporary user name and password if necessary.
(d) Use of transaction safeguards to prevent unauthorized use of passwords and/or identification codes, and to detect and report in an immediate and urgent manner any attempts at their unauthorized use to the system security unit, and, as appropriate, to organizational management.
The user lockout feature after a specified number of consecutive failed logins is a safeguard against unauthorized access to the system. In addition to this feature, you can log any failed login in a system file that the administrator can monitor to be notified of the failed events. 
You can see from the underlined statements that this used to be a feature in the DSC module, but it appears to me that there is no longer any way to disable a user account except through the Domain Account Manager.  Perhaps that is enough to satisfy part (c) of the above regulation now, but it seems like a useful feature to have so that an unauthorized person cannot sit there all day long trying passwords for a specific account.  I have looked through all of the property node and invoke node classes and methods, but could find nothing pertaining to security or user accounts.  A search of the help pages also turns up nothing.  Did I miss something?
In the other passage I underlined, there is a reference to logging failed login attempts to a system file, but again I have not been able to find any kind of reference to how to do this.  Do you have any idea?  The standard read/write files will not work because system log files are generally protected, hidden, or encrypted.  Besides, if the program attempts to write to a system file with user permissions and not administrator permissions it won't work.  If it did work, then the user could just go and alter those system files to erase any record of their doings.  So really, logging failed login attempts in a system file is not a trivial task as the underlined statement above suggests.  Any suggestions would be appreciated...
Thanks,
Craig

Similar Messages

  • How can i set up multiple user accounts for my new ipad mini?

    How can i set up multiple user accounts for my new ipad mini?

    The iPad mini is basically a one user device. There are no Accounts. You can set up restrictions so that only you can do certain things.

  • I use migrate assistant to move files from my old pc to the new Mac , but it creates the user account. How can i delete the unwanted user account.

    i use migrate assistant to move files from my old pc to the new Mac , but it creates the user account. How can i delete the unwanted user account.

    Welcome to Apple Support Communities
    That's the classic behaviour after using Migration Assistant and that's normal.
    To transfer the data from the new user account to your old user account, you can follow some steps. Here is all the information you need to do this > https://discussions.apple.com/docs/DOC-5472

  • How do I make my old user account perform like the new one?

    I have a macbook pro 13" 2008 with 8 gb of ram that has been showing stuttering in hd video lately (or maybe when i upgraded to lion). I created another user and it doesn't seem to suffer any stuttering. Perhaps it doesn't have weird things running the background like the 655mb kernal task I see in activity monitor. My question is, how do I make my old user account perform like the new one? I've tried to turn off things running the background, but it doesn't seem to do anything. Thanks!

    How to Transfer Everything from an Old iPad to New iPad
    http://osxdaily.com/2012/03/16/transfer-old-ipad-to-new-ipad/
    http://ipad.about.com/od/iPad_Guide/ss/How-To-Wipe-Your-iPad-And-Erase-Data.htm
     Cheers, Tom

  • How do I access my encrypted User Account files from my Back Up hard drive?  Time Machine  was used to create the back up disk; File Vault was used to encrypt the files.

    How do I access my encrypted User Account files from my Back Up hard drive?  Time Machine  was used to create the back up disk; File Vault was used to encrypt the files.

    Thanks.  I will try going through TM.  Since my Simpletech is on the way out, I'll be plugging in a new external hard drive (other than the back-up drive) and trying to restore the library to the new drive.  Any advice or warning if this is NOT the right thing to do?
    Meanwhile, that is a great tip to do an alternate back-up using a different means.  It's been tough to figure out how to "preserve access" to digital images and files for posterity, knowing the hardware will always fail/obsolesce sooner or later, and that "clouds" are only as good as their consistent and reliable accessibility.  Upping the odds with redundancy will help dull the edge of my "access anxiety", though logically, it can never relieve it.  Will look into
    Carbon Copy Cloner.

  • How do I eliminate an extra user account i never wanted to create?

    I recently reformatted and reinstalled and re-set up my whole system, and even though I thought i was beng careful to set up as lean a system as possible, I somehow ended up with an extra, unidentified user account at my login screen. I normally log in automatically at startup, but whenever I need to logout and log back in, there's this annoying extra user log in, that, up until this time, I've never had to deal with, as I'm the only one using my computer.  I can't get rid of the blasted thing no matter what I've tried, and there seems to be no documentation covering this mystery, either.  Anybody else run into this problem before, and how did you give this extra user account the boot?

    Those 2 folders are normal, and Aliases.
    Here's a tease of just some of the things that happen when I turn off or on Guest login...
    # Event
      type           = FSE_RENAME
      pid            = 11 (DirectoryService)
      # Details
        # type           len  data
        FSE_ARG_STRING    61  string = /private/var/db/dslocal/nodes/Default/users/Guest.plist.temp
        FSE_ARG_DEV        4  dev    = 0xe00000e (major 14, minor 14)
        FSE_ARG_INO        4  ino    = 17013958
        FSE_ARG_MODE       4  mode   = -rw-------  (0x008180, vnode type VREG)
        FSE_ARG_UID        4  uid    = 0 (root)
        FSE_ARG_GID        4  gid    = 0 (wheel)
        FSE_ARG_STRING    56  string = /private/var/db/dslocal/nodes/Default/users/Guest.plist
        FSE_ARG_DEV        4  dev    = 0xe00000e (major 14, minor 14)
        FSE_ARG_INO        4  ino    = 17013956
        FSE_ARG_MODE       4  mode   = -rw-------  (0x008180, vnode type VREG)
        FSE_ARG_UID        4  uid    = 0 (root)
        FSE_ARG_GID        4  gid    = 0 (wheel)
        FSE_ARG_INT64      8  tstamp = 20233754401813
        FSE_ARG_DONE (0xb33f)
    # Event
      type           = FSE_CREATE_FILE
      pid            = 11 (DirectoryService)
      # Details
        # type           len  data
        FSE_ARG_STRING    54  string = /private/var/db/dslocal/indices/Default/index-journal

  • How do I clear the "recent" user account pictures in Mountain Lion?

    How do I clear the "recent" user account pictures in Mountain Lion? A friend posted a stupid photo as one of the pictures as a joke and I cant figure out how to remove it from the recent pictures.
    Thanks

    To completely remove the files, from the desktop click Go>Go to Folder and type
    ~/Library/Containers/com.apple.ImageKit.RecentPictureService/Data/Library/Images /Recent Pictures/
    Then move the files you don't want to trash.
    Make sure to empty trash and restart before viewing your recents again, or they will reappear.

  • How do i erase my first user account?

    I recently reset my mac to factory settings but now i have to login twice at startup. How do i erase my first user account? Or how do i enable automatic login?

    You must first log out of the account you wish to remove. From the other account open Users & Groups preferences. Click on the lock icon and enter your admin password as requested. Select the account you wish to delete from list then click on the Delete [-] button. Select the last option to completely remove. Do not select Secure Erase sub-option.

  • How can I retrieve my old user account?

    Hi,
    I migrated my old iMac to my new 27" iMac and did it wirelessly via the internet and it took ages. Apple support told me to do it this way because my old iMac is 400 Firewire and my new one only has 800 Firewire and I only had a 400 Firewire cord.
    I was told to choose the no I don't want to migrate when I went through registering my computer. I then got it set up with internet and then went into Migration Assistant. I told the woman I spoke too that it was going to create a problem with my old user account and she said I could just delete it.
    Here is my dilemma. My old user account is called Pink Tuley (which has all my information, documents etc. on it), I created a new account called Tuley and you guessed it it's a shell with nothing there. All my stuff in on Pink Tuley and when I go to MacintoshHD users and locate my Pink Tuley folder there are a bunch of folders that I can't open (they have that red circle with a white bar in the middle of them). How do I make Pink Tuley my main account or get all the Pink Tuley stuff onto my new Tuley account? I hope there is a way to figure this out.

    Niel,
    Thanks that was easy. Now can I go and delete the new user account I created when I first registered this computer? I have a few user accounts from my old machine I don't use, can I delete those also or is it best to leave them alone?
    Message was edited by: spiralgirl

  • How do I create a new user account?

    I have a new iPod with a different iTunes account than my other devices.  How do I sync the iPod on my iMac with the songs/movies from its own iTunes account?  Do I need to create a new user profle on the computer for that?

    As you said, I recommend to create a new user account and create a new iTunes library on that user with the content of the iPod. If you sync it with your user account, you will get on the iPod the content from a different Apple ID and maybe content that you don't want.
    To create a new user account, open System Preferences > Users & Groups, and press the + button that it's below the left sidebar (where users are listed). Then, just follow the steps to set up the user account.
    Now, every time you start your Mac, OS X will ask you the user account you want to start OS X with

  • How do I set up separate user accounts on the same computer

    I would like to set up a separate user account on the same computer with different bookmarks and favorites. Can it be done? How do you do it?
    Thanks, Bobby

    http://www.microsoft.com/windowsxp/using/setup/winxp/accounts.mspx

  • How do I share music between user accounts on the same computer?

    My wife and I have separate user accounts on the same MacBook Pro so that we can both sync our phones to this computer. My account is the primary user account, and my iTunes library is stored in this account. My wife would like to put music on her iPhone so she can run, but I can't seem to access the music library thru her account. I know the files are all on the hard drive regardless, so I just need to know how I can make iTunes on my wife's account access the library that's there. I've tried the steps I could find on Apple's website, but I can't seem to make it work. I'm running the latest versions of everything - even tho the post says I'm running 10.9.1, I'm actually running 10.9.4

    To give other users read-only access to your iTunes library, use the Sharing features of iTunes. Sharing works over the local network as well as on the same computer. See the built-in help for details.
    If you want to give full read/write access to more than one user, see the support article linked below.
    iTunes: How to share music between different accounts on a single computer
    There is a way to share the library without moving it to a secondary volume. If you really need to do that, ask for instructions.

  • How to share Pages with other user accounts

    How to share "Pages"with other user accounts

    When you install it, do it for "Everyone" or in the Admin account.
    Peter

  • How can I find my other user account migrated from another mac?

    I used time machine to backup all the data from my macbook and then I used the migration assistant on my imac and transfer those data to the imac.
    Everything was successful and after that. I can see the new user account under my hard drive > User folder but I dont have privilege to open the file.
    And on the other hand, I got no way to login that user ID.
    How can I fix that?
    thanks

    happygal wrote:
    I used time machine to backup all the data from my macbook and then I used the migration assistant on my imac and transfer those data to the imac.
    Everything was successful and after that. I can see the new user account under my hard drive > User folder but I dont have privilege to open the file.
    And on the other hand, I got no way to login that user ID.
    what do you mean? do you mean the migrated user doesn't show up at the login window? or that the password doesn't work?
    How can I fix that?
    thanks

  • How do i delete the old users account on my second hand imac g5 without the origonal disc

    im new to imacs and not sure how to delete the old users account without the origonal disc

    First of all, you need to make sure your current user account (the one you intend to keep) is an administrator account (not standard).
    Go to System Preferences Accounts pane.  Click the lock, if it's locked, and enter your authorization, to unlock.
    In the sidebar, you will see the list of user accounts.  To delete a user account, select it on the list and click the minus sign.

Maybe you are looking for

  • Material document not updated in inspection lot QALS table

    HI The inspection lot created for 04 inspection type  during Goods Receipt. The material document is appearing in the inspection lot but found not updated in table entries.  i.e.., QALS -MBLNR When i checked other inspection lots it was found updated

  • Copying Variables in BPEL using XPath Query

    Hi, I am new to BPEL and i want to know if it is possible to copy data from one variable to another using XPath Query in the <from> <to> tags, when the two variables are of different message types. I am trying to create a sample BPEL that would recei

  • Different order in the results

    I have a problem with order consistency in the data set on the screen vs. the sequence of records being selected one by one behind the screen. Say, in the first form I select certain "where clause" and several "order by". I pass parameters to the sec

  • UNSPSC code in SRM MDM ?

    Hi, We are in migration from CCM 2.0 SRM MDM. In CCM , we are uploading the catalogs with UNSPSC and material group. Either any one is mandatory. If they give UNSPSC code in catalog, while uploading we are mapping to correspoding material group. But

  • Change Input Text backgroud color

    Hi all, Is it possible change the background color of an Input Textbox at runtime? Something like link the backgroud color to a spreadsheet cell. Thanks, Marcelo Camarate