Re: Default Domain Policy - Password Chg 90 days



write to Microsoft (quoted text) ! ;)

--
Cordialement,
Mathieu CHATEAU
http://lordoftheping.blogspot.com


"Jorge Silva" <jorgesilva_pt@xxxxxxxxxxx> wrote in message news:eXSgd298HHA.1188@xxxxxxxxxxxxxxxxxxxxxxx
Hi
Generally, it's not a good idea to set a password so it doesn't expire because this defeats the purpose of having passwords in the first place.

I don't agree with this....
There're situations when having nonexpiring passwords can save you from trouble, for example for use with service accounts.
--
I hope that the information above helps you.
Have a Nice day.

Jorge Silva
MCSE, MVP Directory Services
"Mathieu CHATEAU" <gollum123@xxxxxxx> wrote in message news:%23XmCxf98HHA.980@xxxxxxxxxxxxxxxxxxxxxxx
Hello,

this setting is for user, and this is the only place it works.

Maximum password age
http://technet2.microsoft.com/windowsserver/en/library/039e8d42-fe50-4738-abf3-c798e74a03f61033.mspx?mfr=true

You are speaking about password history, which is different from the age

Enforce password history
http://technet2.microsoft.com/windowsserver/en/library/8a3d5451-14bd-4f89-8f55-dc6261dbd4fc1033.mspx?mfr=true

the password never expires override GPO:
http://www.microsoft.com/technet/prodtechnol/windows2000serv/deploy/confeat/08w2kadb.mspx

Password Never Expires If selected, the password for this account never expires. This setting overrides the domain account policy. Generally, it's not a good idea to set a password so it doesn't expire because this defeats the purpose of having passwords in the first place.
--
Cordialement,
Mathieu CHATEAU
http://lordoftheping.blogspot.com


"al" <al@xxxxxxxxxxx> wrote in message news:1189446416.273216.43600@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
W2k3 Native Mode Domain: From what I understand, the default domain
policy that contains the setting "Maximum password age" 90 days really
applies to computer objects and NOT user objects. Which allows for
backwards compatability. So where does the user get their password
history enforcement from? They are required to change their passwords
every XX days in our domain but now I am not too sure where they are
getting this from if the above setting is only applied to computer
objects and local accounts. I've heard that this is set in a domain
profile? The reason I am asking is that we have some accounts that we
set "password never expires" on and I want to know how this overrides
a domain GPO. There is not an OU GPO that allows for this exception -
there is no exception.

TIA
al





.



Relevant Pages

  • Re: Default Domain Policy - Password Chg 90 days
    ... because this defeats the purpose of having passwords in the first place. ... for example for use with service accounts. ... Password Never Expires If selected, the password for this account never ...
    (microsoft.public.windows.server.active_directory)
  • Re: Error when putting AD user attribites to Excel
    ... AccountExpirationDate is a property method. ... This property method returns the date/time when the account expires (the ... On Error GoTo 0 ... sheet with all accounts with the experation dates in it. ...
    (microsoft.public.scripting.vbscript)
  • Re: AD 2000, Blank passwords, and Group Policy
    ... the original creator of these accounts set them to 'Password ... never expires' so that won't work for me. ... I'm going to have to use your suggestion of disabling the policy ... > file though you may want to post in a Windows scripting newsgroup for that You might ...
    (microsoft.public.win2000.security)
  • Re: Password Change Policy
    ... > You can set the password never expires attribute on the accounts services ... >> next logon" setting for multiple users at a single time? ... It will affect all accounts except ... >> setting up a password change policy. ...
    (microsoft.public.win2000.active_directory)
  • Re: Default Domain Policy - Password Chg 90 days
    ... Mathieu CHATEAU ... There are certain accounts that have ... Or is it used for local accounts ... > user - it is NOT being done through local GPOs. ...
    (microsoft.public.windows.server.active_directory)

Loading