Re: How can I disable (grey out) the "Password never expires" chec

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Its not so much that they don't comply but rather to meet the security
policy....I know it doesn't quite make sense :)

These boxes can be greyed out as they are under certain cirumstances, like
the Admin account on a DC etc. Perhaps this can only be done via the API??


"Herb Martin" wrote:

> "CrazyKiwi" <CrazyKiwi@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
> news:5FE3B26F-2D56-4362-A837-E6EFE956F4D6@xxxxxxxxxxxxxxxx
> > Hi,
> >
> > We are trying to enforce our password policy so that all accounts
> including
> > administrator accounts HAVE to change their passwords every 90 days. How
> can
> > I disable (gray out) the "Password never expires" checkbox in the User
> > Account properties windows so that the admins cannot bypass the password
> > expiry policy by checking "Password never Expires"
>
> You probably cannot.
>
> How many admins to you have?
>
> Education (of these admins) is likely the key.
>
> You can take away their admin privileges if they
> don't comply...<grin>
>
>
>
.



Relevant Pages

  • Re: Weird security problem in my WIn2K domain
    ... Keep in mind that enterprise admins group has no administrative powers on ... Another thing to try is to create a new account ... add that account to the local administrators ... enable auditing of account logon events in Domain Controller Security Policy ...
    (microsoft.public.windows.server.security)
  • Re: Problem managing accounts in protected groups
    ... For you administrator accounts create an own OU directly under the domain name and place there the domain admin accounts without any restrictions through policies or whatever. ... And create for them a normal domain user account for the daily work with normal restrictions like any other user. ... If now the account under the Administrators OU is locked another one from that OU can easily unlock them without any problem, because they all are domain admins in that OU. ... heard about that someone will give more security permissions to users ...
    (microsoft.public.windows.server.active_directory)
  • Re: Login as local admin
    ... schema admins, enterprise admins and the other groups mentioned, but the ... installing SBS SP1. ... So if i basically ensure that my domain administrator account is a member ... The article does not reference "local" administrator (as far as I ...
    (microsoft.public.windows.server.sbs)
  • Re: [Full-disclosure] Flaw in Microsoft Domain Account Caching Allows Local Workstation Admins t
    ... Local admins become LOCAL ADMINS by using a cached domain account who is a LOCAL ADMIN. ... domain users that have local administrator privileges on domain assets ...
    (Full-Disclosure)
  • RE: [Full-disclosure] Flaw in Microsoft Domain Account Caching Allows Local Workstation Admins t
    ... Local admins become LOCAL ADMINS by using a cached domain account who is a LOCAL ADMIN. ... domain users that have local administrator privileges on domain assets ...
    (Bugtraq)