Active Directory: Customize the Password must meet complexity requirements

Posted on 2010-09-01
Medium Priority
Last Modified: 2012-05-10

I am looking to customize the Password must meet complexity requirements option in AD 2003 and 2008.  

We need to take out the Non-alphabetic characters from this policy.  

does anyone know how I can change the DLL for the policy?  and do you have instruction?
Question by:SEHC
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
LVL 22

Expert Comment

by:Matt V
ID: 33578226
You change this in the group policy setting.  Usually in the default domain policy object.  Through group policy management console.

Expert Comment

ID: 33578233
You can configure the password policy settings in the following location in the Group Policy Object Editor:

Computer Configuration\Windows Settings\Security Settings\Account Policies\Password Policy

If you’re on a stand-alone machine (no AD etc) and dealing with only local accounts, you can enable/disable the policy from:

Administrative Tools -> Local Security Policy -> Account Policies -> Password Policy.

Have a look at KB from microsoft
LVL 57

Accepted Solution

Mike Kline earned 1000 total points
ID: 33578537
So you won't just be able to take the non-alphabetic characters out.  You will have to disable password must meet complexity requirements (in the domain linked GPO that others have mentioned)
 [eBook] Windows Nano Server

Download this FREE eBook and learn all you need to get started with Windows Nano Server, including deployment options, remote management
and troubleshooting tips and tricks

LVL 85

Assisted Solution

oBdA earned 1000 total points
ID: 33578863
Unless you feel like writing your own passfilt.dll, you'll have to resort to 3rd-party tools like "Password Policy Enforcer" (http://www.anixis.com/products/ppe/default.htm) or "Specops Password Policy" (http://www.specopssoft.com/web/specops-password-policy.aspx).

Author Comment

ID: 33579090
is there a way to write a passfitt.dll?  do you have and links I can look at?
LVL 57

Expert Comment

by:Mike Kline
ID: 33579129
If you want to attempt to do it yourself (if you have a strong programming backgorund) start here
 I've personally never tried it.
LVL 85

Expert Comment

ID: 33579279
An example is here (requires free registration); should still work with W2k3:
Enforce Custom Password Policies in Windows

But note especially the "Before you implement" section on page 2:
"Consider the following issues before you start coding your own Password Filters:
* Expect the unexpected. Because LSA loads password filters during start-up, if something goes wrong, your system may become inoperable or go into deadlock. To avoid this, develop and test your DLLs on machines that have at least two operating systems installed.

And if you're comparing DIY with prices for a 3rd-party tool, don't forget to take into account how much it costs if your AD comes to a grinding halt because of a malfunction in the filter (and who'll have to take all the blame for it).
LVL 26

Expert Comment

ID: 34532803
This question has been classified as abandoned and is being closed as part of the Cleanup Program.  See my comment at the end of the question for more details.

Featured Post

Use Case: Protecting a Hybrid Cloud Infrastructure

Microsoft Azure is rapidly becoming the norm in dynamic IT environments. This document describes the challenges that organizations face when protecting data in a hybrid cloud IT environment and presents a use case to demonstrate how Acronis Backup protects all data.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Auditing domain password hashes is a commonly overlooked but critical requirement to ensuring secure passwords practices are followed. Methods exist to extract hashes directly for a live domain however this article describes a process to extract u…
After seeing many questions for JRNL_WRAP_ERROR for replication failure, I thought it would be useful to write this article.
This tutorial will walk an individual through locating and launching the BEUtility application to properly change the service account username and\or password in situation where it may be necessary or where the password has been inadvertently change…
This tutorial will walk an individual through setting the global and backup job media overwrite and protection periods in Backup Exec 2012. Log onto the Backup Exec Central Administration Server. Examine the services. If all or most of them are stop…
Suggested Courses
Course of the Month9 days, 23 hours left to enroll

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question