Re: Maximum password age - Need Proof

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



You cannot currently set a password policy for a single OU let alone a single domain user account.

--
Joe Richards Microsoft MVP Windows Server Directory Services
Author of O'Reilly Active Directory Third Edition
www.joeware.net


---O'Reilly Active Directory Third Edition now available---

http://www.joeware.net/win/ad3e.htm


Jetze Mellema (MS MVP) wrote:
"Franky M." <FrankyM@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message news:18C0A950-BADA-4628-8582-D5EA8A615614@xxxxxxxxxxxxxxxx
I have the Maximum password age set to 90 days and I'm sure it's working fine
YET the CIO wants to see proof that it's working.
He wants something like an entry in Event Viewer showing the forcing of a
password due to the policy.

What can I do?

Make a similar GPO and set the maximum password age very low, i.e. 1 day. Let the GPO apply to his account and he will notice in less than one day.
.



Relevant Pages

  • Re: Oh.... Im just wondering whos seen this stumper...
    ... Joe Richards Microsoft MVP Windows Server Directory Services ... he was explicit write permissions. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Preventing Users from removing their PC from the Domain
    ... Joe Richards Microsoft MVP Windows Server Directory Services ... Author of O'Reilly Active Directory Third Edition ... results, no disable if no creds, disable with creds. ...
    (microsoft.public.win2000.security)
  • Re: converting SID
    ... Joe Richards Microsoft MVP Windows Server Directory Services ... IIRC you can only write to sIDHistory when creating an object. ...
    (microsoft.public.windows.server.active_directory)
  • Re: SID history
    ... Joe Richards Microsoft MVP Windows Server Directory Services ... Author of O'Reilly Active Directory Third Edition ... I prefer adfind because it includes a -binenc switch that will display the SIDs in a much more readable format than you might get otherwise. ...
    (microsoft.public.windows.server.active_directory)
  • Re: How to purge a mailbox programatically
    ... Joe Richards Microsoft MVP Windows Server Directory Services ... My guess is that this WMI class is calling a routine in a private serverside library the hard part is finding documentation for all the steps that library performs when it does a purge. ...
    (microsoft.public.exchange.development)