Jump to content

Recommended Posts

Posted

Need to change the password length on our domain to stop the pupils setting their password to blank. I have changed this in their pupil policy but they still can do it. Im guessing its in the DD policy that i need to change?

Only concern is what knock on effect this has on anything else,

Will this force our domain admin accounts to need to be changed?

If i change it to say 6 characters will this force all passwords lower than this to change?

 

Not changed a DD policy before so just airing on the side of caution!! :)

 

cheers

Posted (edited)

You do indeed need to set it in the Default Domain Policy, as is my understanding of the basic password policies. As far as I'm aware this is the ONLY thing that you should ever really change in the default domain policy.

 

You can also use fine grained password policies if your domain controller is 2008 or newer. I'd suggest googling "Fine grained password policies" :) (Set a minimum blanket policy in the default domain policy, then use fine grained policies to tighten security for specific groups further)

 

EDIT: Just checked, actually looks like it doesn't have to be in the default domain policy. It just needs to be in a policy that's at the root of the domain, but there appears to be no harm in editing the pre-existing settings in the default domain policy. (as they exist there from creation of a domain if i remember correctly)

Edited by mrbios
Posted

Thanks for all your replies on this - just one last question, what effect does it have to users that have a password below the minimum password policy? Does it make them change this at next logon? (once i make the change). Or is it at next password reset?

 

Cheers

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...