AD User Password Policies



Greetings.

I have questions RE applying Password Policies. I have an AD running on 2
2k+3 DC's. First:

-I notice that a group policy to control user passwords is actually a
machine policy. What would be the best OU to apply this to? I have separate
OU's for users and machines.

-I want users to reset passwords every 30 days, but the annoying pop-up
comes TWO WEEKS before they are required to change their password. Is this
time limit hackable?

Thanks a lot.
.