Solved

Active Directory: Customize the Password must meet complexity requirements

Posted on 2010-09-01
9
1,973 Views
Last Modified: 2012-05-10
HI,

I am looking to customize the Password must meet complexity requirements option in AD 2003 and 2008.  

We need to take out the Non-alphabetic characters from this policy.  

does anyone know how I can change the DLL for the policy?  and do you have instruction?
0
Comment
Question by:SEHC
9 Comments
 
LVL 22

Expert Comment

by:Matt V
Comment Utility
You change this in the group policy setting.  Usually in the default domain policy object.  Through group policy management console.
 
0
 
LVL 7

Expert Comment

by:simonseztech
Comment Utility
You can configure the password policy settings in the following location in the Group Policy Object Editor:

Computer Configuration\Windows Settings\Security Settings\Account Policies\Password Policy

If you’re on a stand-alone machine (no AD etc) and dealing with only local accounts, you can enable/disable the policy from:

Administrative Tools -> Local Security Policy -> Account Policies -> Password Policy.

Have a look at KB from microsoft
http://technet.microsoft.com/en-us/library/cc264456.aspx
0
 
LVL 57

Accepted Solution

by:
Mike Kline earned 250 total points
Comment Utility
So you won't just be able to take the non-alphabetic characters out.  You will have to disable password must meet complexity requirements (in the domain linked GPO that others have mentioned)
http://technet.microsoft.com/en-us/library/cc786468(WS.10).aspx
Thanks
Mike
0
 
LVL 82

Assisted Solution

by:oBdA
oBdA earned 250 total points
Comment Utility
Unless you feel like writing your own passfilt.dll, you'll have to resort to 3rd-party tools like "Password Policy Enforcer" (http://www.anixis.com/products/ppe/default.htm) or "Specops Password Policy" (http://www.specopssoft.com/web/specops-password-policy.aspx).
0
The curse of the end user strikes again      

You’ve updated all your end user’s email signatures. Hooray! But guess what? They’re playing around with the HTML, adding stupid taglines and ruining the imagery. Find out how you can save your signatures from end users today.

 
LVL 4

Author Comment

by:SEHC
Comment Utility
is there a way to write a passfitt.dll?  do you have and links I can look at?
0
 
LVL 57

Expert Comment

by:Mike Kline
Comment Utility
If you want to attempt to do it yourself (if you have a strong programming backgorund) start here
http://msdn.microsoft.com/en-us/library/ms721882(VS.85).aspx
 I've personally never tried it.
Thanks
Mike
0
 
LVL 82

Expert Comment

by:oBdA
Comment Utility
An example is here (requires free registration); should still work with W2k3:
Enforce Custom Password Policies in Windows
http://www.devx.com/security/Article/21522/0/page/1

But note especially the "Before you implement" section on page 2:
"Consider the following issues before you start coding your own Password Filters:
[...]
* Expect the unexpected. Because LSA loads password filters during start-up, if something goes wrong, your system may become inoperable or go into deadlock. To avoid this, develop and test your DLLs on machines that have at least two operating systems installed.
[...]

And if you're comparing DIY with prices for a 3rd-party tool, don't forget to take into account how much it costs if your AD comes to a grinding halt because of a malfunction in the filter (and who'll have to take all the blame for it).
0
 
LVL 26

Expert Comment

by:Pber
Comment Utility
This question has been classified as abandoned and is being closed as part of the Cleanup Program.  See my comment at the end of the question for more details.
0

Featured Post

Are end users causing IT problems again?

You’ve taken the time to design and update all your end user’s email signatures, only to find out they’re messing up the HTML, changing the font and ruining the imagery. What can you do to prevent this? Find out how you can save your signatures from end users today.

Join & Write a Comment

In this article, we will see the basic design consideration while designing a Multi-tenant web application in a simple manner. Though, many frameworks are available in the market to develop a multi - tenant application, but do they provide data, cod…
A procedure for exporting installed hotfix details of remote computers using powershell
This tutorial will walk an individual through the steps necessary to enable the VMware\Hyper-V licensed feature of Backup Exec 2012. In addition, how to add a VMware server and configure a backup job. The first step is to acquire the necessary licen…
This tutorial will walk an individual through setting the global and backup job media overwrite and protection periods in Backup Exec 2012. Log onto the Backup Exec Central Administration Server. Examine the services. If all or most of them are stop…

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now