Re: Set password restrictions

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance




"APT SA" <APTSA@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:809ABBFC-E039-404E-941C-936FDAECED88@xxxxxxxxxxxxxxxx
I want to use group policy to set password restrictions (max pass age) but
I
do not want this to effect my service accounts and admin accounts. I have
created a separate OU for these accounts. But from what I understand you
have to set these restritions on the domain controller policy.

That is incorrect. It must be set on a DOMAIN (not DC) GPO, i.e.,
a GPO linked to the domain container if you wish it to affect your domain
accounts.

So won't this
make my service account passwords expire b/c they must authenticate from
DC
as well? If so how do I get around this. I must be missing something
basic.

Not if you have set them to "password never expires".

In general, service accounts should have EXTREMELY long and complex
passwords and "never expire." (My rule is that if even I myself can
remember
the password for more than a few minutes it is much too easy.)


.



Relevant Pages

  • Re: Cluster services with expiring passwords
    ... The corporate auditing requires that service accounts have their passwords ... I have a two-node SQL Server clustering and I'm looking for a way to ... check "Password never expire" on the account properties. ...
    (microsoft.public.windows.server.clustering)
  • Re: Domain Password Policy
    ... Create service accounts with REALLY strong passwords. ... expire, if you need to. ...
    (microsoft.public.windows.server.general)
  • Service accounts with password expiration
    ... If I modify passwords for clustering service accounts, ... keep running with no disruption? ...
    (microsoft.public.security)
  • Re: Manage user account service password ?
    ... it is typical to configure service accounts to have ... Joe Kaplan-MS MVP Directory Services Programming ... Co-author of "The .NET Developer's Guide to Directory Services Programming" ... an easy solution to change service passwords every 3 months for example? ...
    (microsoft.public.windows.server.active_directory)
  • Re: physical security
    ... You do not need tools to hack the dit-db, and ipsec just helps you to ... To retrieve the passwords I'll just need to start ... To prevent him to get the other accounts ... as passwords for your service accounts you can use very ...
    (microsoft.public.windows.server.active_directory)