Re: Password Policy Enforcement Question



Hi

-When you change the rules, those rules will be applied to user s the next
time they try to change their Password (regarding to complexity option).
-The password expiration is calculated by comparing the policy to the
pwdLastSet attribute and checking the current time and date at the point of
authentication.
- password last changed date + maximum password age
- For example if you change the password expiration to 60 days, anyone who
last changed their password 60 or more days ago will be expired when you
implement the policy. If you have not expired passwords in the past, this
could expire most users.
--
===================================
I hope that the information above helps you.
Have a Nice day.


Jorge Silva
MCSE, MVP Directory Services
===================================
"Paul" <pauldi@xxxxxxxx> wrote in message
news:5837d853-14e0-4b46-8bc0-eda8fdf8046c@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Greetings,

I am about to implement a strict password policy on my Windows 2003 AD
domain. I was wondering if this takes effect immediately and will
lock out all users without "strong" passwords, or if it will allow the
old passwords to remain active for the period outlined in the policy
and then require a strong password upon expiration.

If it is the former, is there a way to prevent this? I have no doubt
in my mind that the majority of users have weak passwords and locking
them all out at once would be bad. Thanks.


.



Relevant Pages

  • Re: Password never expires-cant force user to change password
    ... Password policy on the domain for domain users is all or nothing. ... You want to implement a new password expiration policy. ... > Expire your departments manually. ... I'm just not a very good script writer and am not very confident. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Active Directory Expiration Notification
    ... a map of all attributes that can be set via the policy files agaiinst the ... Co-author of "The .NET Developer's Guide to Directory Services Programming" ... message to the user that their password is about to expire. ... Password expiration is determined by the domain password expiration ...
    (microsoft.public.windows.server.active_directory)
  • Re: Domain account policy
    ... this could expire most users. ... The password expiration is calculated by comparing the policy to the ... password last changed date + maximum password age. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Password never expires-cant force user to change password
    ... Password policy on the domain for domain users is all or nothing. ... You want to implement a new password expiration policy. ... > Expire your departments manually. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Password Expiration on 5.2
    ... dissemination or other use of, or taking of any action in reliance upon, this ... "Weeks between password EXPIRATION and LOCKOUT" means that after a password ... I am trying to setup all user to have their password expire every 30 ... retransmission, dissemination or other use of, or taking ...
    (AIX-L)