Active Directory Extend Password Expiration in Default Domain Group Policy


hello all,

i going change "password expiration" on default domain policy 90 days 180 days. affect users in domain.  i have tested out in qa environment , had no negative results saw. did not force test accounts used change passwords, additionally there not noticibale changes required after extending policy.

could tell me if have extended "password expiration" policy on "default domain policy" , if had negative effects on active directory domain environment.

thank in advance


matt burgos

hi matt,
if set password policy in default domain policy, me, might has no negative effects on active directory domain environment long value of maximum password age exceeds setting minimum password age.
however, if domain have been set fine grained password policy, may need change maximum password age there, because if have both default domain password policy , fine-grained password policies in place, fine grained password policy takes precedence.
best regards,
wendy

please remember mark replies answers if , un-mark them if provide no help. if have feedback technet subscriber support, contact tnmff@microsoft.com.



Windows Server  >  Directory Services



Comments

Popular posts from this blog

server manager error: ADAM.events.xml could not be enumerated.

Cannot access Anywhere Access using domain name?

WMI Failure: Unable to update Local Resource Group