question

CCMSSCCMSS-2117 avatar image
0 Votes"
CCMSSCCMSS-2117 asked FanFan-MSFT commented

How to override the default domain password policy

I have a Windows 2016 server as a domain controller. I tried to set a password policy to a dedicated OU, the ROSP shown the policy has been acquired successfully but it is not working. It still follow the password setting in the default domain policy.

windows-group-policy
· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Hi,
 
Just checking in to see if the information provided was helpful.
 
If the reply helped you, please remember to accept it as an answer.
If no, please reply and tell us the current situation in order to provide further help

Best Regards,

0 Votes 0 ·
AbhijeetSinghKohli-MSFT avatar image
0 Votes"
AbhijeetSinghKohli-MSFT answered

Hi @CCMSSCCMSS-2117 , The password policy is applied at the domain level. If you want to configure a separate password policy for users, you need to use Fine Grained Password Policy. Refer https://docs.microsoft.com/en-us/windows/security/threat-protection/security-policy-settings/password-policy.

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

FanFan-MSFT avatar image
0 Votes"
FanFan-MSFT answered FanFan-MSFT commented

Hi,

All account policies settings (include the password policy) applied by using Group Policy are applied at the domain level.

Each domain can have only one account policy. The account policy must be defined in the default domain policy or in a new policy that is linked to the root of the domain and given precedence over the default domain policy, which is enforced by the domain controllers in the domain. These domain-wide account policy settings (Password Policy, Account Lockout Policy, and Kerberos Policy) are enforced by the domain controllers in the domain; therefore, domain controllers always retrieve the values of these account policy settings from the default domain policy Group Policy Object (GPO).

As you tested ,If these policies are set at any level below the domain level in Active Directory Domain Services (AD DS), they affect only local accounts on member servers.

You can use fine-grained password policies to specify multiple password policies in a single domain and apply different restrictions for password and account lockout policies to different sets of users in a domain.
For more details you can refer to :https://docs.microsoft.com/en-us/archive/blogs/canitpro/step-by-step-enabling-and-using-fine-grained-password-policies-in-ad

Best Regards,

· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Hi,
Welcome to share your current situation if there are any updates.
Please feel free to let us know if you need further assistance.
 
Best Regards,

0 Votes 0 ·