Jump to content

Recommended Posts

Posted

Greetings all.

 

Has anyone implemented Fine Grained Password Policy in Server 2012? Is it really as simple as it looks/sounds?

 

At the moment we only have the following enabled Minimum password length and Password must meet complexity requirements on Domain Policy.

 

Can FGPP & Domain Policy work together like this?

 

Thanks

Manny

Posted
I've implemented it and yes, it really is as simple as it sounds. Create the FGPP, assign it to an AD group, assign the policies a priority to determine which policy takes precedence if someone is a member of multiple groups and off you go.
  • Thanks 1
Posted (edited)

That will depend on the age of the user's password. If it's older than the setting in the FGPP, yes. If not, no, they will have to change it at the next expiry point.

 

If you want people to change their passwords immediately, you will have to check the "User must change password at next logon" box on their accounts. You would be able to script this.

Edited by Norphy
  • Thanks 2
Posted
That will depend on the age of the user's password. If it's older than the setting in the FGPP, yes. If not, no, they will have to change it at the next expiry point.

 

If you want people to change their passwords immediately, you will have to check the "User must change password at next logon" box on their accounts. You would be able to script this.

 

Thanks for the info.

 

You mention this:

If you want people to change their passwords immediately, you will have to check the "User must change password at next logon" box on their accounts.

 

I can't see that option when creating a new password setting in ADAC. Where are you referring this to?

 

Thanks

Manny

  • 10 months later...
Posted

Hi,

 

I have just setup FGPP. I have set the maximum password age to 365 so they change passwords once a year. I've set the complexity requirements and minimum password length but it isn't applying to certain individuals.

 

If they already meet the criteria and their password isn't over a year old they won't be prompted?

If their password is under a year old but don't meet the complexity requirements will they be prompted?

 

Regards,

Posted
Hi,

 

I have just setup FGPP. I have set the maximum password age to 365 so they change passwords once a year. I've set the complexity requirements and minimum password length but it isn't applying to certain individuals.

 

If they already meet the criteria and their password isn't over a year old they won't be prompted?

If their password is under a year old but don't meet the complexity requirements will they be prompted?

 

Regards,

 

The prompt has to be setup on the Domain Policy GPO, like so:

 

Domain Policy.JPG

 

And the FGPP setup in Active Directory Administrative Center, like so:

 

Admin Centre.JPG

 

But because we expired everyone's password immediately after turning on the Policy, not sure how the promts would have worked without expiring the passwords.

 

Manny

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...