Re: Password policy

From: Byron Hynes [MS] (bhynes_at_online.microsoft.com)
Date: 10/22/05


Date: Fri, 21 Oct 2005 21:54:45 -0700

If we are talking about DOMAIN ADMINISTRATORS who have been advised that
the passwords need to change every 60 days, and have not changed them themselves,
they should be able to figure out the "You must change your password" prompt
when it appears after they log in.

These accounts should not be used for logons to laptops or roaming devices
or airport kiosks.

Byron Hynes
Windows Server
Microsoft Corporation

http://spaces.msn.com/members/byronphynes

> As Joe and Byron have pointed out, you need to run a script or program
> to force the passwords to expire after the specified number of days.
> The problem with this approach is that users are not warned that their
> password is about to expire. This may or may not be a problem for your
> users. We are working on a solution to this problem for a future
> version of Password Policy Enforcer.
>



Relevant Pages

  • Re: PwdLastSet
    ... AD Password expiration is handled in a very simple way and done when a user attempts to log on (or their account is otherwise trying to auth). ... Now I simply compare pwdLastSet against that value and anything less than it is expired. ... Directory: Windows Server 2003 ...
    (microsoft.public.win2000.active_directory)
  • Re: PwdLastSet
    ... user attempts to log on (or their account is otherwise trying to auth). ... it is the attribute called maxPwdAge. ... it is expired. ... Directory: Windows Server 2003 ...
    (microsoft.public.win2000.active_directory)
  • =?iso-8859-1?Q?Re:_What_happens_when_a_user=B4s_password_expires=3F?=
    ... BLOG --> http://blogs.dirteam.com/blogs/jorge/default.aspx ... Always test ANY suggestion in a test environment before implementing! ... I have a Windows server 2003 domain, with passwords set to expire every ...
    (microsoft.public.windows.server.active_directory)
  • Re: Expiration Date for Windows 2000 MCSE
    ... Famous last words: "Hey, check this out!" ... > So the exams for w2k MCSE do not expire in November 2005? ... >> finish up with the two exam upgrade for Windows Server 2003. ...
    (microsoft.public.cert.exam.mcse)
  • Re: Saved Queries - reprieved user account
    ... It indicates the day/time an account is supposed to expire meaning the value is constantly changing for what is currently expired or if you want to check for something that will expire in the future that hasn't expired yet. ... Joe Richards Microsoft MVP Windows Server Directory Services ... Is there a LDAP string I can use as a saved query? ...
    (microsoft.public.windows.server.active_directory)

Loading