jmak Posted April 16, 2015 Posted April 16, 2015 Hi I'm trying to set up a different set of password rules for pupils compared to staff - the staff rules work reasonably well, but we're about to move to individual logins for all of our infant age pupils. Their passwords will be their d.o.b. in the format ddmm and set to never expire. The current password policy is set at the top domain level - in a policy called default domain policy - which I don't really want to change. (The original set of GPOs was set up before my time by someone who knows more than I aspire to and matches the standard build for our LA. I have added, but not significantly changed, as I want someone else to be able to come in and manage the server if I'm not around.) I have created a GPO with the settings: Computer Configuration/Policies/Windows Settings/Security Settings/Account Policies/Password Policy: Password history: 0 Passwords Max age: 0 Min age: 0 Min length: 4 characters Complexity requirements: Disabled I can log onto a test account with a password that I have set to meet the domain requirements. However I am unable to set a password as I want it. I have linked this to my test user OU and set to enforced, disabled GPO inheritance on that OU, run GPUpdate /force When I try to change the password, I get the error message: Windows cannot complete the password change for test user because: The password does not meet the password policy requirements. Check the minimum password length, password complexity and password history requirements. What am I doing wrong? Thanks
Killer_Bot Posted April 29, 2015 Posted April 29, 2015 I'm fairly sure you can only have one Password Policy on the domain. If you want to allow for different levels you need to use Fine Grained Passwords. You just create Password Setting Objects and reference them to a group (of which the users are in). So in our case we have a PSO for Students that allows them to have far less complex passwords than our Staff. You'll need to create them directly in ADSIEdit with Server 2008 R2 unless you use a third party tool. Once they're created it will override the default domain settings for those users only. Full details here; Fine-Grained Password Policy in Windows Server 2008/2008R2 | iSiek's blog about Microsoft Windows services 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now