Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
Solved

How can I change password complexity so that password must contain characters from all four categories

Posted on 2009-07-13
2
382 Views
Last Modified: 2012-06-21
Normally when you activate "password complexity" in a windows domain you demand that the password contains characters from three out of four categories (UPPERCASER, lowercase, numbers, numbers and non-alfabetic characters).

Is there a way to change it so that all four categories must be met?
0
Comment
Question by:Joffer
2 Comments
 
LVL 20

Assisted Solution

by:MightySW
MightySW earned 100 total points
ID: 24840979
Sorry, no.  This is complexity and you cannot enforce this on users.

This is by design.

Know you didn't want to hear this, but this is the way that it is.  Unless someone out there has some sort of non-MS .adm template to do this you cannot enforce all 4.  

In a way, this is done by the security policy.  

There may be a way to have this scripted and checked on the login script.  You might want to resubmit this under scripting.  They may have a better answer.

HTH
0
 
LVL 12

Accepted Solution

by:
Gideon7 earned 150 total points
ID: 24844126
The only solution I can think of is to write your own credential provider (CP) to enforce your custom password-complexity policy.
A good overview on writing a CP can be found at http://msdn.microsoft.com/en-us/magazine/cc163489.aspx.  See especially the discussion of a "hybrid implementation", which describes how to customize the existing default CP to fit your needs.
0

Featured Post

Back Up Your Microsoft Windows Server®

Back up all your Microsoft Windows Server – on-premises, in remote locations, in private and hybrid clouds. Your entire Windows Server will be backed up in one easy step with patented, block-level disk imaging. We achieve RTOs (recovery time objectives) as low as 15 seconds.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Disabling the Directory Sync Service Account in Office 365 will stop directory synchronization from working.
In-place Upgrading Dirsync to Azure AD Connect
This tutorial will walk an individual through locating and launching the BEUtility application to properly change the service account username and\or password in situation where it may be necessary or where the password has been inadvertently change…
This tutorial will walk an individual through setting the global and backup job media overwrite and protection periods in Backup Exec 2012. Log onto the Backup Exec Central Administration Server. Examine the services. If all or most of them are stop…

789 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question