Re: Howto Determine AD User Accts Having Passwords < 6 characters

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Hello mcintoshs,

Never heard about such a tool and hopefully it wan't exist. Configure the policy setting on domain level and inform your users about the new setting.

The next time they are requested to change the password or change it manual they have to use the new length.

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


I am dealing with a legacy Active Directory implementation in which
the prior
administrator failed to implement mimimum password character length.
Our plan
is to notify users a month or so in advance that they need to change
their
password to one with at least 6 characters and if they fail to do so
by a
date certain they will no longer be able to login to the network.
The problem is that there are many 'generic' accounts which do not
correspond to a live user and there are even more accounts not having
e-mail
addresses so the notification process will be torturous.
What I need is a safe and proven utility which can scan Active
Directory and
list every user account in the domain which has less than 6
characters. I
also need instructions on how to use the utility for that purpose.
Thanks,
Scott


.



Relevant Pages

  • Re: Applying Group Policy to OU
    ... must put the User accounts - not the Group account - in the OU. ... you apply the GPO at the domain level, then it will apply to all domain user ... accounts who have the Read and Apply Group Policy permissions. ...
    (microsoft.public.windows.server.general)
  • Re: Password policy at the OU level
    ... password policy is enforced at the domain controllers. ... How do I handle service accounts? ... >>within a GPO linked to the domain level only. ...
    (microsoft.public.windows.group_policy)
  • Re: Question about GPO and password policies
    ... on a large number of user accounts? ... Password policies are set at the domain level, ... That said, you can select multiple accounts in ADUC, ...
    (microsoft.public.windows.server.active_directory)
  • Re: Different Password Policy for Domain versus sub-Domain
    ... If a script were written to set accounts to 'passwords do not expire' would this override the group policy at the domain level. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Password length Change Not reflecting
    ... If the policy is set on domain level it should work. ... GPO updates can take up to 90 minutes before they are refreshed without rebooting or using gpupdate. ... as i'm able to chnage the password with 6 characters even..Can someone ...
    (microsoft.public.windows.server.active_directory)