Re: Re: Changing the domain password policy



You deal with the Service Account passwords by making them comply with your password policy.

A point to note - 1 domain 1 password policy.
you can create as many different password policies as you like - the Domain Password Policy will be the one actually applied to all users.


----- Original Message ----- From: "Mike Devlin" <mdevlin@xxxxxxxxxx>
Cc: <security-basics@xxxxxxxxxxxxxxxxxxxxxxx>
Sent: Friday, February 02, 2007 7:17 PM
Subject: [Norton AntiSpam] Re: Changing the domain password policy


yes, you are right that if you change the password complexity requirements/minimum length, all the accounts that don't meet the new requirements are fine until their password expires or is forced to rotate. I suppose that if you wanted to be extra safe, you could make a policy just for the service accounts, and have a different set of password requirements for these accounts, and have the default domain policy have the stronger password complexity settings.

- Mike

Gary Collis wrote:
Hi All,

I wish to amend my windows domain policy to include passowrd complexity and minimum length. However I have a bunch of service accounts, of which I do not know all. These passswords are set in AD to not expire. Am I right in thinking that the changes to the domain password policy will not effect the accounts that have this attribute set in AD, until these passwords are actually changed?

How do other people deal with service accounts and their adherence to domain password policys?

Thanks,





Relevant Pages

  • Re: Password policy at the OU level
    ... Checkpoint issues with PPTP go back to the origin, ... >I would suggest that either you get their outbound VPN ... >password policy is enforced at the domain controllers. ... How do I handle service accounts? ...
    (microsoft.public.windows.group_policy)
  • Re: Enforce "Password Never Expires" Setting?
    ... This feature allows you to configure a different password policy to a user or group. ... So in your case, you would have to create a shadow group, add all your service accounts to the shadow group, create a PSO that sets the maximum password age to 0, and apply the PSO to the shadow group that you created. ... logoff script would seem moot since the service account never actually logs ...
    (microsoft.public.windows.group_policy)
  • Domain Password Policy
    ... The only password policy we currently enforce in our 1 domain is a minimum ... Minimum password length - 8 characters ... We currently have numerous damain service accounts that do NOT meet the ...
    (microsoft.public.win2000.security)
  • RE: Changing the domain password policy
    ... You can't "change" the password policy in Active Directory Users and ... password resets in Active Directory Users and Computers ARE affected by ... Changing the domain password policy ... How do other people deal with service accounts and their adherence to ...
    (Security-Basics)
  • RE: Group Policy: multiple password policies in the same domain?
    ... > There can be only one password policy for the domain. ... > (backup, Exchange, SQL Server, Scheduled Tasks, etc.) where I ... > service accounts have a certain password policy while regular ... > Derick Anderson ...
    (Focus-Microsoft)