mansin Posted March 23, 2018 Posted March 23, 2018 Greetings all. Has anyone implemented Fine Grained Password Policy in Server 2012? Is it really as simple as it looks/sounds? At the moment we only have the following enabled Minimum password length and Password must meet complexity requirements on Domain Policy. Can FGPP & Domain Policy work together like this? Thanks Manny
Norphy Posted March 23, 2018 Posted March 23, 2018 I've implemented it and yes, it really is as simple as it sounds. Create the FGPP, assign it to an AD group, assign the policies a priority to determine which policy takes precedence if someone is a member of multiple groups and off you go. 1
badders Posted March 23, 2018 Posted March 23, 2018 Does it apply the policy straight away, are users suddenly asked to change their password?
Norphy Posted March 23, 2018 Posted March 23, 2018 (edited) That will depend on the age of the user's password. If it's older than the setting in the FGPP, yes. If not, no, they will have to change it at the next expiry point. If you want people to change their passwords immediately, you will have to check the "User must change password at next logon" box on their accounts. You would be able to script this. Edited March 23, 2018 by Norphy 2
mansin Posted March 23, 2018 Author Posted March 23, 2018 That will depend on the age of the user's password. If it's older than the setting in the FGPP, yes. If not, no, they will have to change it at the next expiry point. If you want people to change their passwords immediately, you will have to check the "User must change password at next logon" box on their accounts. You would be able to script this. Thanks for the info. You mention this: If you want people to change their passwords immediately, you will have to check the "User must change password at next logon" box on their accounts. I can't see that option when creating a new password setting in ADAC. Where are you referring this to? Thanks Manny
mansin Posted March 23, 2018 Author Posted March 23, 2018 See attachment Thanks Norphy. Test policy has worked a treat and will be looking to deploy after Easter.
Manny-Tech Posted February 6, 2019 Posted February 6, 2019 Hi, I have just setup FGPP. I have set the maximum password age to 365 so they change passwords once a year. I've set the complexity requirements and minimum password length but it isn't applying to certain individuals. If they already meet the criteria and their password isn't over a year old they won't be prompted? If their password is under a year old but don't meet the complexity requirements will they be prompted? Regards,
mansin Posted February 7, 2019 Author Posted February 7, 2019 Hi, I have just setup FGPP. I have set the maximum password age to 365 so they change passwords once a year. I've set the complexity requirements and minimum password length but it isn't applying to certain individuals. If they already meet the criteria and their password isn't over a year old they won't be prompted? If their password is under a year old but don't meet the complexity requirements will they be prompted? Regards, The prompt has to be setup on the Domain Policy GPO, like so: And the FGPP setup in Active Directory Administrative Center, like so: But because we expired everyone's password immediately after turning on the Policy, not sure how the promts would have worked without expiring the passwords. Manny
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now