User Accounts And Domain Password Policies

| | No TrackBacks
Password policies for user accounts in Active Directory environment are controlled by group policy settings located at

Computer Configuration\Windows Settings\Security Settings\Account Policies\Password Policy

There are six policies there. They affect all the domain users and normally there are no means to exempt an account from the policies.

The only exception: if you check 'Password never expires' setting on the user's properties in Active Directory Users and Computers, domain setting for maximum password age can be overridden for that user.

However, this can lead to certain security breaches, so the option should only be used for services accounts only; for even more security, event logs should be monitored for any authentication attempts for such 'never-expiring' accounts.

No TrackBacks

TrackBack URL: /blog/mt-tb.cgi/33

blog comments powered by Disqus

About this Entry

This page contains a single entry by Konstantin Boyandin published on December 14, 2009 1:43 PM.

User Profiles For Service Accounts was the previous entry in this blog.

Pre-Staging Computer Accounts is the next entry in this blog.

Find recent content on the main index or look in the archives to find all content.