Solved

Resetting Domain password

Posted on 2009-04-02
10
306 Views
Last Modified: 2013-12-04
Hi all,

I want my 200 domain users to change their password every 60 days but I need to ensure that some important users & the administrator accounts are not affected.

I am also aware that there is a option in the user properties " Password do not expire ". Would this option be override when a domain policy is implemented ?

Thanks.
0
Comment
Question by:Elminster73
10 Comments
 
LVL 14

Expert Comment

by:MCSA2003
ID: 24056064
Create a GPO that includes the requirements you have indicated. Appky the GPO to the specific users, leaving the Admin accounts not applied to the policy. As far as the passwords set to never expire, it all depends on what GPO the Admin accounts are set to follow.
0
 
LVL 17

Expert Comment

by:Andres Perales
ID: 24056085
Agree with MCSA, but I would create OU's first, one for normal users and other OU's for your service / admin accounts, this will be easier to manage than by individual accounts.
0
 
LVL 18

Expert Comment

by:Americom
ID: 24056117
If you have windows 2000/2003 domain, password policy can only work when it is link to the domain level. One domain  password policy per domain. Of course, if you have Windows 2008 domain then you are a bit more flexible when comes with doamin users password policy.
0
Ransomware: The New Cyber Threat & How to Stop It

This infographic explains ransomware, type of malware that blocks access to your files or your systems and holds them hostage until a ransom is paid. It also examines the different types of ransomware and explains what you can do to thwart this sinister online threat.  

 
LVL 18

Expert Comment

by:Americom
ID: 24056131
Also, yes, if you set the account password never expire, the GPO will not override this feature. However, it is generally not recommended but it can be avoided being prompt to change password.

btw, if password policy applied to OU with machines such as workstation or member servers, it affect the local users account of those machine but not domain users.
0
 

Author Comment

by:Elminster73
ID: 24057588
Hi all,

Thanks for your reply. But can someone tell me how to reset my 200 domain users password without afftecting the important accounts. Currently my servers are on Windows 2000 / 2003. Is there a script that I can use to make it simplier to reset them ?

Thanks.

0
 
LVL 16

Expert Comment

by:speshalyst
ID: 24059018
0
 
LVL 18

Expert Comment

by:Americom
ID: 24059752
As I have mentioned in my above posts, you can exclude the user account from gettting prompt to chagne password by going to the user account object and check "Password never expire". This is the only way to exclude in a domain without using 3rd party product. Unless you have Windows 2008 as mentioned from my above post.
0
 
LVL 54

Accepted Solution

by:
McKnife earned 175 total points
ID: 24083361
"Is there a script that I can use to make it simplier to reset them ?" - yes. You can execute it at the DC and it will force the option "user must change password at next logon" to be set. I would (temporarily) seperate the accounts into seperate OUs and then execute http://www.microsoft.com/technet/scriptcenter/guide/sas_usr_akke.mspx?mfr=true
0
 
LVL 18

Assisted Solution

by:Americom
Americom earned 175 total points
ID: 24083633
The script McKnife provided will enable and prompt those 200 users to change password upon their next domain logon, assuming you have those 200 users account in the specified OU where you run the script.
If any user just changed password recently, they also will get prompted to change password, so you may want to send out communication prior to forcing users to change password to avoid calls.

Also, is that's all you need or have you enabled or adjusted the password policy to force users to change password every 60 days as state in your questions? If not, you may want to enable the password policy to change password every 60 days before running the above script. As I have stated above, to make users change password every 60 days is a domain policy which will affect all users unless you check the box of the user account to have "Password never expire".

0
 

Author Closing Comment

by:Elminster73
ID: 31566093
Hi guys,
Thank you very much for your help and helpful tips.
0

Featured Post

Free Tool: Port Scanner

Check which ports are open to the outside world. Helps make sure that your firewall rules are working as intended.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
VMWare Calculate number of processors 10 70
How can i confirm Password policy is working? 8 17
active directory 6 14
Find enabled users in a OU 24 19
Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
This article shows the method of using the Resultant Set of Policy Tool to locate Group Policy that applies a particular setting.
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

820 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question