Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Password Changes in windows 2003 Server AD

Posted on 2011-09-15
3
Medium Priority
?
240 Views
Last Modified: 2012-05-12
For the longest we have been setting up user’s passwords to never expire; now we would like to force users to change their passwords every 30 days. I am currently running Active Directory on a Windows 2003 Server; but there are a few users that I don’t want to force, is there a way for me to do this or is this change made for all? Also when I make this change do I have to do anything to the users account in order for this change to take place?

Thanks

0
Comment
Question by:ahmad1467
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 57

Accepted Solution

by:
Mike Kline earned 2000 total points
ID: 36545035
Just keep the box checked for "password never expire" for those users that you don't want to change the password.     That checkbox will trump the change to every 30 days.

Once you set the policy you don't have to make any other modifications to the user accounts to make the change happen other than making sure the the password never expire is unchecked if you want them to change.

Thanks

Mike
0
 
LVL 1

Expert Comment

by:praveen_16july
ID: 36548237
Hi ahmad,

Use the Group Policy Management
under the Computer Configuration -> Windows Settings -> Account Policies/Password Policy ->
set Maximum Password Age = 30

For the Case of exclude some users:
go to Group Policy Management -> go to the delegation tab -> Add users (which you want to exclude) -> clik on the advanced tab -> select users which you want to exclude -> check the deny boxs. after that those users not affected with this policy.

if you need any help please let me know.
0
 

Author Comment

by:ahmad1467
ID: 36550660
I have a server that I set shares for in AD but I have a few people that use Macs so I give them access through local users. Is there a way to push this to the local users from the Group Policy Management?
0

Featured Post

How Blockchain Is Impacting Every Industry

Blockchain expert Alex Tapscott talks to Acronis VP Frank Jablonski about this revolutionary technology and how it's making inroads into other industries and facets of everyday life.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A hard and fast method for reducing Active Directory Administrators members.
In the absence of a fully-fledged GPO Management product like AGPM, the script in this article will provide you with a simple way to watch the domain (or a select OU) for GPOs changes and automatically take backups when policies are added, removed o…
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…
Suggested Courses

715 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question