Jump to content

Recommended Posts

Posted (edited)

I'm looking at setting up fine grained password policies in 2012R2. At the moment password policies are still done in the plain old "Default Domain policy" section.

 

A couple of questions:

Once fine grained policies are configured, do i need to remove the settings in the default domain policy? or should i just set these to be the same as the minimum strength settings out of my fine grained policies groups?

 

Secondly, let's say i add a fine grained policy for a group that's stronger than the currently defined settings in the default domain policy, what happens when someone's password doesn't meet the complexity requirements? Are they asked to change their password on next logon? are all users asked to change their password on next logon regardless of the change?

 

I don't want to throw myself in at the deep end and find that setting the policy causes all staff and all students to have to reset their password the next morning :p Although presumably this is the sort of thing that's best changing in a holiday and pre-warning people weeks in advance.

 

EDIT: Lastly, how do you have yours setup?

Edited by mrbios
Posted

I'm looking at setting up fine grained password policies in 2012R2. At the moment password policies are still done in the plain old "Default Domain policy" section.

 

A couple of questions:

Once fine grained policies are configured, do i need to remove the settings in the default domain policy? or should i just set these to be the same as the minimum strength settings out of my fine grained policies groups? LEAVE THEM, THEY WILL APPLY TO ANYONE THE FINE GRAIN POLICY DOESN'T APPLY TO

 

Secondly, let's say i add a fine grained policy for a group that's stronger than the currently defined settings in the default domain policy, what happens when someone's password doesn't meet the complexity requirements? Are they asked to change their password on next logon? are all users asked to change their password on next logon regardless of the change? CHANGES WILL BE FORCED HAS BEEN MY EXPERIENCE

 

I don't want to throw myself in at the deep end and find that setting the policy causes all staff and all students to have to reset their password the next morning :p Although presumably this is the sort of thing that's best changing in a holiday and pre-warning people weeks in advance. I DID IT OVER THE LAST WEEKEND OF A HALF TERM AND MADE EVERYONE CHANGE ON THE INSET DAY THAT FOLLOWED

 

EDIT: Lastly, how do you have yours setup

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...