Questions about domain password policies



Hello Everyone,

I have a couple of questions about domain password policies.

Understanding that account policies must be applied at the domain
level, I have the following questions:

1. If management requests that the implementation of a password policy
be staggered so as to avoid an overwhelming amount of support calls,
can the new password policy be applied only to specific groups?

2. If password aging has been set in the new policy, does the clock
start counting the day that the policy is implemented or does it take
into consideration the amount of time that a password has already been
used? For example, if userA set his password in January of 2001 and
the administrator at his company implements a new policy today with a
90 day maximum age for passwords, is he prompted to change his
password the next time that he logs on or must he actually change the
password first before the counter begins?

3. Do account settings ("password never expires", "user cannot change
password") override account policies?

That's all. Any help would be greatly appreciated!

.



Relevant Pages

  • Re: Security Policy for OU?
    ... The DCs pull this info. from the domain; not from a specific linked GPO ... Assuming that the policy can be linked, my question is based on Ulf's assertion that: "The account policies for domain users only apply if they are in the default domain policy." ... > be recreated in the default domain policy of the child domain? ...
    (microsoft.public.windows.server.active_directory)
  • Re: Maximum password age
    ... At what level did you check for the Account Policies ie using RSOP ... So open the Default Domain Policy from AD Users and Computers, ... > Gautam Anand ... > | When I originally set securitry settings I didn't change the maximum ...
    (microsoft.public.windows.group_policy)
  • Re: Problem with Group Policies
    ... Account Policies is at the GPO linked to the domain, ... with some settings not being applied from a Default Domain Policy. ... I have created a Default Domain Policy at the root Domain and have applied ...
    (microsoft.public.win2000.group_policy)
  • Re: Password Policies
    ... Account policies are one to a domain. ... level only take affect when the user logs onto a computer in that OU ... would this mean that the computers in the Remote Users OU would ... > excluded from the sitewide Password Policy rules as defined in the Default ...
    (microsoft.public.win2000.security)
  • Re: Group password reset
    ... Set the domain password policies to expire passwords in 1 week (turn ... this policy off after 6 days). ... Create a logon script similar to the above, ...
    (microsoft.public.security)