User password attribute?



Hi

A security audit in company states that a large amount of users are
allowed to use weak/zero passwords.

The domain policy setting says that weak/zero password isn't allowed!

Here is the clue:
A closer look shows that a "weak/zero password user" can't make a weak
password by them self.
But an administrator CAN do it, by reseting the password. Have tried
that.

It seems to be users who have been auto-created / migrated who have
this "weak/zero password" possibility (old users - created for some
years ago).

On a new created user couldn't even the administrator make a weak/zero
password for the user. This is normal.

Want to stop the possibility for setting weak/zero passwords by
helpdesk and administrator peoples.

Any idea about which user attribute to look for or ideas to solve this
behavior ?

Regards
John
.