Solved

What is the impact to change the policy Maximum Password Age 60 Days to 0 Day?

Posted on 2014-12-16
6
143 Views
Last Modified: 2014-12-16
Hello everyone,

I need to change temporarily to complete a migration password policy Maximum Password Age 60 Days to 0 days.

What will be the impact on users?

You will be prompted immediately for users to change the password?

I tried to find some official Microsoft document and found nothing about it.

Could someone show me an official documentation on the impact of this change?

Thank you very much.
0
Comment
Question by:lucianolima
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
6 Comments
 
LVL 24

Assisted Solution

by:Phillip Burton
Phillip Burton earned 250 total points
ID: 40502464
I believe that 0 days means "never expires". In other words, they won't be prompted to change the password, because they don't need to.

See http://technet.microsoft.com/en-gb/library/cc736566%28v=ws.10%29.aspx for more information.
0
 
LVL 7

Expert Comment

by:HaiFai
ID: 40502467
If you set it to 0 password neverexpire so minimum days is 1 max 998

http://technet.microsoft.com/en-us/library/cc736566%28v=ws.10%29.aspx
0
 
LVL 1

Author Comment

by:lucianolima
ID: 40502511
I had also found such documentation, but they are not clear regarding the exchange I need to do.

In theory I agree with you and make much sense this, but as I cannot reproduce this scenario and particularly I have never done this type of change to 0 days I am concerned about the impact this may cause to users.

Has anyone done this in practice?
0
Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

 
LVL 24

Accepted Solution

by:
VB ITS earned 250 total points
ID: 40502516
Yep, I have. Setting it to 0 days just means their passwords will never expire as stated above. They will continue to be able to use their existing password without any issues.
0
 
LVL 1

Author Closing Comment

by:lucianolima
ID: 40502525
Thank you very much All.

I will make the changes in the days and warning everyone about the result.
0
 
LVL 1

Author Comment

by:lucianolima
ID: 40502594
Hello everyone,

I was able to reproduce the changes in a lab environment.

Before you change the Password Policy I ran the command:

net user% USERNAME% / domain

The result was display the expiration date of the account:

Password Expires --> 1/13/2015 10:00:30 PM

Then I changed the Password Policy and execute gpupdate/force in Domain Controller and ran the command again and the result was showing that the password never expires.

Password Expires --> Never
0

Featured Post

Resolve Critical IT Incidents Fast

If your data, services or processes become compromised, your organization can suffer damage in just minutes and how fast you communicate during a major IT incident is everything. Learn how to immediately identify incidents & best practices to resolve them quickly and effectively.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

To effectively work with Diskpart on a Server Core, it is necessary to write some small batch script's, because you can't execute diskpart in a remote powershell session. To get startet, place the Diskpart batch script's into a share on your loca…
I was supporting a handful of Windows 2008 (non-R2) 2 node clusters with shared quorum disks. Some had SQL 2008 installed and some were just a vendor application that we supported. For the purposes of this article it doesn’t really matter which so w…
This tutorial will show how to configure a new Backup Exec 2012 server and move an existing database to that server with the use of the BEUtility. Install Backup Exec 2012 on the new server and apply all of the latest hotfixes and service packs. The…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…

751 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question