troubleshooting Question

Can you apply a password policy for Wk3 AD to most users but choose exclusions?

Avatar of iteaoa
iteaoaFlag for United States of America asked on
OS SecurityWindows Server 2003Active Directory
6 Comments1 Solution458 ViewsLast Modified:
Hello. We are trying to tighten the security for our domain. We are running 2k3 native AD. It is my understanding that you can only have one password policy per AD domain. I'm ok with the password policy stength applying to all users, but I'd like to exclude our admin-level accounts from having to change every 90 days. Is there a way to apply the policy to end users ONLY, and exclude admin-level accounts? We had been using our "default domain policy" to define the password policy, and it is targeted to the "authenticated users" security group.

I tried removing the password specifics from the default domain policy, and creating a new GPO that would have the password settings defined, and then tried to link it to a group of users I created for this called "Password_GPO". But running GPRESULT from a workstation shows that the default domain policy is applied whereas the other GPO is ignored. I assume this is because the default policy targets "authenticated users", which means if you log on, it is applicable.

Any help would be appreciated. Thanks!

Our community of experts have been thoroughly vetted for their expertise and industry experience.

Join our community to see this answer!
Unlock 1 Answer and 6 Comments.
Start Free Trial
Learn from the best

Network and collaborate with thousands of CTOs, CISOs, and IT Pros rooting for you and your success.

Andrew Hancock - VMware vExpert
See if this solution works for you by signing up for a 7 day free trial.
Unlock 1 Answer and 6 Comments.
Try for 7 days

”The time we save is the biggest benefit of E-E to our team. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange.

-Mike Kapnisakis, Warner Bros