GPO Password Expiration vs. Active Directory ADUC password expiration.


say have active directory user account named joe.  there domain policy passwords must changed every 6 months.  when @ joe's account in active directory users , computers has password expiration set on 1 year away. (someone has manually set account expire radio button in aduc)

is joe's password 6 months or 1 year?

password expiration different account expiration. unless have fine grained password policy configured joe, password expire in 6 months, , joe need change then. account expire after year, , unusable, unless admin changes or removes account expiration.

edit: not see max password age in user account properties in aduc. must view properties of domain object domain settings, such maxpwdage.


richard mueller - mvp enterprise mobility (identity , access)





Windows Server  >  Group Policy



Comments

Popular posts from this blog

server manager error: ADAM.events.xml could not be enumerated.

Cannot access Anywhere Access using domain name?

WMI Failure: Unable to update Local Resource Group