Re: Advise to password policy



The policy that governs password aging is applied all or none to all
accounts in the domain. Therefore GPO filtering, or multiple GPOs,
will not accomplish what you are after. Your idea about using never
expires, while laborious, would work.

Some have suggested that a good user information campaign before
enabling password expiration can get users to change their passwords
beforehand, having been warned that otherwise they will face having
to deal with their passwords being expired on day-one of the new
policy being applied.

Another thing one can do is to use a staged expiration.
Suppose you want eventually to have a 90 expiration, and you see
that on some future implementation day the oldest password will be
130 days old. How would expirations turn out if you set the expiration
period at 120 day initially, and then reduced this by 5 days each week
until you were at 90 ?? so that over a six week period any account that
had a password older than 48 days when you started would have had
to change.



"David" <David@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:90DEC7E5-2B19-4EA9-A793-3495D70C676E@xxxxxxxxxxxxxxxx
Hi all,

will be implementing password policy in my single Win2k3 domain.
I had a total 200 over user accounts with most of them over the 90 days
password expiry limit.

I would like to implement the password policy in phrases according to
departments.
Perhaps using the AD user account "password never expire" field or GPO
security filtering.

Anyone has any views on this type of implementation?


.



Relevant Pages

  • RE: Group Policy: multiple password policies in the same domain?
    ... > it under access to the GPO. ... The conflict only happens when both policies ... results in having the policy denied. ... > user accounts it affects be able to read it and have "apply ...
    (Focus-Microsoft)
  • Re: Strong Passwords
    ... You can always tell which part of a GPO must be enabled by ... I'll setup a new Policy at the domain level. ... > "Roger Abell" wrote: ... >> impact only on the machine local accounts of machines in the OU. ...
    (microsoft.public.security)
  • Re: Exclude from GPO ..
    ... I only put in the user accounts that should not have the ... Users" group is assigned with Read and Apply Group Policy ... ... I then created a new GPO with the settings I ... need to password protect a screen saver to go off at 15 minutes. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Default Domain Policy Question
    ... > Domain controllers read password policy from the domain ... Account policies when GPO is linked to the DC OU. ... > There can only be one policy per domain for domain accounts. ...
    (microsoft.public.windows.group_policy)
  • RE: GPO settings are not applied
    ... Microsoft Windows XP Operating System Group Policy Result tool v2.0 ... GPO: Automatic_Updates ... GPO: Default Domain Policy ... Secure Proxy Server: N/A ...
    (microsoft.public.windows.server.active_directory)