LukeMoss Posted April 27, 2022 Posted April 27, 2022 Hi all, I know blank passwords aren't the greatest and they aren't used much in our environment, but we have the need for certain uses to have an account with a blank password (nursery, KS1) I appreciate if we give them a password they'll learn it, but that isn't a way teachers want to go and currently no backing to enforce this. Down to the issue, I have tried creating a user with a blank password as I usually do but for some reason this time I am unable to due to the complexity, history etc requirements. The domain policy hasn't changed and this is set to minimum password length as 0, there are no fine grained policies enforced and the policy applied to the user is minimum length 0. Has anybody had this before? Not sure where else to look to begin to diagnose as there is no logs in event viewer either for the failure to create the user. Currently running Server 2016 Thanks in advance, Luke
Katy Posted April 27, 2022 Posted April 27, 2022 Have you checked for any of the fine-grained password policies? One of the more recent (2012 I think?) additions, you can apply password policies to groups rather than the entire domain. It's in AD Admin Centre, Domain > System > password settings container:
TriggerHappyUK Posted April 27, 2022 Posted April 27, 2022 You can exclude the users from the password GPO. If the password rules are in the Default GPO, you can create a new GPO just for the password rules and exclude the users there. Then just remove the password rule bits from the Default GPO
LukeMoss Posted April 27, 2022 Author Posted April 27, 2022 Hi @Katy, yes I've checked that and no fine grained password policies are applied to the user. Thanks though! @TriggerHappyUK The password rules are applied through the default domain policy, but the setting is set to 0 with Lithnet over arching, but with this disabled I still don't get the expected result of setting a blank password.
Katy Posted April 27, 2022 Posted April 27, 2022 We used to give the reception kids all the same, very short password (like "tree" or something), maybe that's an answer if you can't get a blank one to work. Pretty sure the teacher/TA had to help every kid type their username, so the password just happened at the same time.
TriggerHappyUK Posted April 27, 2022 Posted April 27, 2022 @TriggerHappyUK The password rules are applied through the default domain policy, but the setting is set to 0 with Lithnet over arching, but with this disabled I still don't get the expected result of setting a blank password. In my experience, changes to GPOs can take a bit of time to work.
LukeMoss Posted April 27, 2022 Author Posted April 27, 2022 @Katy, again thanks for the reply.. That looks like how I may have to go, just seems odd that it's only started happening over the last week or so as I definitely added users without a password about 3 weeks ago with no changes. @TriggerHappyUK, most definitely.. Normally have no issues, it's been left an hour or so and I normally get the desired effect even with a gpupdate /force. The policy doesn't seem to be applying from Lithnet as the minimum on there is 8 and it allows me to use a space so there's only one character.
LukeMoss Posted April 27, 2022 Author Posted April 27, 2022 Ok, strangely I can create a new user with no password using the 'Active Directory Administrative Center' with no password and I receive no error, which surely shows no password policy is in place stopping it?
Oaktech Posted April 27, 2022 Posted April 27, 2022 Why have a blank password, if they can type a username they can type a short password like 'red' or an easy sequence? One of my sites we enforce a 3 character, unchangeable, non complex, password for years R-4. For years 5 & 6 we enforce 8 characters minimum, non complex, changeable. The other sites we enforce 8 characters non complex, changeable for all years.
LukeMoss Posted April 27, 2022 Author Posted April 27, 2022 Why have a blank password, if they can type a username they can type a short password like 'red' or an easy sequence? One of my sites we enforce a 3 character, unchangeable, non complex, password for years R-4. For years 5 & 6 we enforce 8 characters minimum, non complex, changeable. The other sites we enforce 8 characters non complex, changeable for all years. Totally appreciate what you're saying, it isn't the best method as I originally mentioned. I will look into doing something like this, but still my issue remains. It is now more of a I know it can be done so why isn't it working like it should.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now