Solved

AD password complexity and covering my butt

Posted on 2014-04-24
4
320 Views
Last Modified: 2014-04-24
Pretty sure I know the answer to this one but just looking for a confirmation from other experts.

Im about to make a change to the AD password length and complexity GPO. Im pretty sure flipping this on will only affect users once their password is expired and needs to be changed. Anyone whos password still is within the expiration limit will be able to use the non-complex password until the day their password needs to be changed. Then complexity will be required.

Am I right, just double checking before pulling the trigger.
0
Comment
Question by:Joseph Daly
4 Comments
 
LVL 16

Assisted Solution

by:gurutc
gurutc earned 166 total points
ID: 40020143
You're right.  As long as you're using the built-in password management.  Other tools like SpecOps can be more finicky.

- gurutc
0
 
LVL 9

Assisted Solution

by:stu29
stu29 earned 167 total points
ID: 40020145
You are correct.  This will only apply when they are prompted to change it or you try to change someones
0
 
LVL 29

Accepted Solution

by:
becraig earned 167 total points
ID: 40020164
0
 
LVL 35

Author Closing Comment

by:Joseph Daly
ID: 40020191
Thanks guys. Always like to double and triple check these things.
0

Featured Post

Optimizing Cloud Backup for Low Bandwidth

With cloud storage prices going down a growing number of SMBs start to use it for backup storage. Unfortunately, business data volume rarely fits the average Internet speed. This article provides an overview of main Internet speed challenges and reveals backup best practices.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
Is your Office 365 signature not working the way you want it to? Are signature updates taking up too much of your time? Let's run through the most common problems that an IT administrator can encounter when dealing with Office 365 email signatures.
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question