?
Solved

How do I create a script to flag accounts to require passwords and force expirations?

Posted on 2009-04-18
4
Medium Priority
?
243 Views
Last Modified: 2012-05-06
I need to make a script for default domain policy to force all local accounts within all domain PC's to have the passwordreq flag as well as remove the "password never expires" flag.

I have been searching the interwebs with no luck.

Note that I am, at best, a novice in this area.  Any help is appreciated!
0
Comment
Question by:whitman911
2 Comments
 
LVL 81

Accepted Solution

by:
arnold earned 1000 total points
ID: 24179750
I think this is possible with vbscript to connect through the AD and adjust the settings as you mentioned.  I think there was an EE article that discussed this.
Here are different scripting examples that you could use to build the script to do the tasks you want:
http://www.computerperformance.co.uk/vbscript/vbscript_user_create.htm
www.computerperformance.co.uk/Logon/VBScript/VBScript_Windows_passwords.htm
www.activexperts.com/activmonitor/windowsmanagement/adminscripts/usersgroups/users/
www.sysoptools.com/ad-query.aspx

In your case, you do not need to expire passwords since you suggest that you had the never-expire options set.

Note, you should do a group of users at a time rather than forcing all to change their password at once.  Also note to make sure not to expire service accounts.
0
 
LVL 65

Assisted Solution

by:RobSampson
RobSampson earned 1000 total points
ID: 24180977
This may help too:
How Can I Configure an Active Directory Account So the Password Never Expires?
http://www.microsoft.com/technet/scriptcenter/resources/qanda/oct06/hey1031.mspx

Regards,

Rob.
0

Featured Post

Cyber Threats to Small Businesses (Part 1)

This past May, Webroot surveyed more than 600 IT decision-makers at medium-sized companies to see how these small businesses perceived new threats facing their organizations.  Read what Webroot CISO, Gary Hayslip, has to say about the survey in part 1 of this 2-part blog series.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Active Directory replication delay is the cause to many problems.  Here is a super easy script to force Active Directory replication to all sites with by using an elevated PowerShell command prompt, and a tool to verify your changes.
Container Orchestration platforms empower organizations to scale their apps at an exceptional rate. This is the reason numerous innovation-driven companies are moving apps to an appropriated datacenter wide platform that empowers them to scale at a …
The viewer will learn how to create a basic form using some HTML5 and PHP for later processing. Set up your basic HTML file. Open your form tag and set the method and action attributes.: (CODE) Set up your first few inputs one for the name and …
In this fifth video of the Xpdf series, we discuss and demonstrate the PDFdetach utility, which is able to list and, more importantly, extract attachments that are embedded in PDF files. It does this via a command line interface, making it suitable …
Suggested Courses
Course of the Month16 days, 2 hours left to enroll

850 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question