Solved

Password Expiration Policy

Posted on 2014-10-10
7
128 Views
Last Modified: 2014-10-19
Good afternoon Experts,

We had been requested to lower the max age for password from 120 days to 90 days. Upon looking through group policies on our Server 2008 R2 Domain Controller I cannot find any policies with this max age setting. I have combed through all policies for the users who reported that previously they were prompted to change password and can not find any settings for this. Running a RSOP on a few of these users the only references to a password policy for for minimum length, complexity requirements, and lockout policy (see RSOP screenshot attached). I have confirmed through the Active Directory Administrative Center that these users are in fact some how getting a setting that marks their password to expire after 120 days. I am wondering if anyone has any ideas for tracking down where this is coming from in group policy or is there another way to do this that the previous administrator may have configured?

Thanks!
0
Comment
Question by:PCNS_Tech
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
  • 2
7 Comments
 
LVL 58

Expert Comment

by:Cliff Galiher
ID: 40373462
You didn't attach anything. But it sounds like someone set up fine-grained password policies, which in 2008 R2, is not in a clean GUI.

http://technet.microsoft.com/en-us/library/cc770394(v=WS.10).aspx
0
 

Author Comment

by:PCNS_Tech
ID: 40373671
I have read through that article and located this Password Settings Container in AD and using ADSI Edit but it does not appear anything is set within here. Any other ideas?
0
 
LVL 58

Expert Comment

by:Cliff Galiher
ID: 40373726
If fine grained policies are not set then the only policy that controls domain accounts is the "default domain policy." Settings in any other policy are simply ignored.
0
PeopleSoft Has Never Been Easier

PeopleSoft Adoption Made Smooth & Simple!

On-The-Job Training Is made Intuitive & Easy With WalkMe's On-Screen Guidance Tool.  Claim Your Free WalkMe Account Now

 
LVL 15

Expert Comment

by:ZabagaR
ID: 40375827
Open the group policy manager from your domain controller. See my 2 screenshots. What does your password policy show here? Can you take a screenshot and post.  My 2 screenshots are (1) displaying the default domain policy settings tab. On the other screenshot I right-clicked my default domain policy and picked edit.  Then I picked my way down the computer settings and expanded password policies. This is a test DC for me where I have max set to 0 days (which means no max).
policy-settings.jpg
0
 
LVL 15

Expert Comment

by:ZabagaR
ID: 40375833
My above post continued....I think I found a glitch in Experts-Ex because whenever I tried to add my 2nd screenshot, the "add" ability was actually off of the bottom of the screen so I could never click the box to complete adding. I even tried tabbing and using the return key. Oh well.  Here's my 2nd screenshot of editing my default dom group policy.
edit-domain-pass-policy.jpg
0
 

Accepted Solution

by:
PCNS_Tech earned 0 total points
ID: 40380483
I did look in the default domain policy but no max password age is configured. I found an article on someone experiencing this issue (Dont have the link). The just of the article was that if no max age is specified or if set to 0 it will assign a random expiration. I moved the PC's for our users to their own OU and applied a custom password policy for them to work around this. Thanks for everyones help.
0
 

Author Closing Comment

by:PCNS_Tech
ID: 40389778
Worked around the issue.
0

Featured Post

Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Background Information Recently I have fixed file server permission issues for one of my client. The client has 1800 users and one Windows Server 2008 R2 domain joined file server with 12 TB of data, 250+ shared folders and the folder structure i…
Had a business requirement to store the mobile number in an environmental variable. This is just a quick article on how this was done.
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.

734 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question