Jump to content

Recommended Posts

Posted

I've been asked to look into a way of forcing staff user account passwords to expire every 90 days. I did a bit of research and found the option I need in Computer Config -> Policies -> Windows Settings -> Security Settings -> Account Policies -> Password Policy. I've set test values and applied the GPO to my machine for testing but it doesn't seem to be applying.

 

Having checked gpresult the GPO is listed under 'Denied GPOs' with reason 'Empty'.

 

Any ideas?

 

Thanks for any help.

Posted

The policy that you're looking at there is domain wide. It needs to be set in the default domain group policy. You can't apply it to sub-OUs.

 

What you want are fine grained password policies. Those are applied against security groups. Details here: AD DS: Fine-Grained Password Policies

 

You need a Windows 2008 or above domain.

  • Thanks 2
Posted
The policy that you're looking at there is domain wide. It needs to be set in the default domain group policy. You can't apply it to sub-OUs.

 

What you want are fine grained password policies. Those are applied against security groups. Details here: AD DS: Fine-Grained Password Policies

 

You need a Windows 2008 or above domain.

 

Thanks for your reply. Will read up on it.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...