Solved

Domain password policy .vs. Active Directory user profile account "password never expires"

Posted on 2011-09-06
3
1,263 Views
Last Modified: 2012-05-12
I have some concerns regarding modification to an existing GPO policy that retains the settings for passwords. I will be modifiing the policy to enforce stronger complexity requirements. this is only policy driving password restrictions as im sure there can only be one at the domain level.

 My question is: "Password Never Expires" is checked off for every user account, will the GPO setting override Password Never Expires in the user account forcing the user to change thier password or even possibly locking out the accounts? I am in a Windows 2008 AD. My current policy will be overwritten by the new settings and most my users don't meet the complexity that I will be implementing.
0
Comment
Question by:itsupport1144
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 57

Accepted Solution

by:
Mike Kline earned 200 total points
ID: 36492369
If the users have password never expire checked then they can basically use their current password forever.  If you modify the complexity setting then the next time they have to set their password they will need to use a complex password.

By the way in a windows 2008 domain (2008 domain functional level) you can use fine grained passwords to have different passwords for different users/groups   http://technet.microsoft.com/en-us/library/cc770842(WS.10).aspx

Thanks

Mike
0
 
LVL 5

Expert Comment

by:jake77444
ID: 36492396
As mkline said it will only require them to make a more complex password the next time they change it.  But remember if "Password Never Expires" they are not required to change it so they could leave it the same forever.  Editing the GP shouldn't lock the accounts out or cause any effects of that nature.

You could simply remove password never expires from all users, expire all passwords and force them to change the passwords.
0
 

Author Comment

by:itsupport1144
ID: 36496728
Mike...perfect just what i wanted to hear. I was almost certain what you stated was correct before i even posted but just needed that verification before I throw the switch on...Thank you guys very much for your prompt reponse.

Jake,

Yes at the moment everbody dose have the password never expires checked off but that is why i'm taking care of this task to remove what's currently in place and not cause chaos for all my end users.
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
exchange, active directory 3 52
LDAPS Server 2012 R2 Error 0 6 60
AD account Auto logoff 1 39
make computer member of specific domain group after joining domain 8 27
This article describes my battle tested process for setting up delegation. I use this process anywhere that I need to setup delegation. In the article I will show how it applies to Active Directory
A project that enables an administrator to perform actions within a user session context not just at the time of login but any time later on day(s) or week(s) later.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …

733 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question