January 19, 2014

Password Policy How to use it on Domain Controller

Password Policy
Go to Start – Program – Administrative Tools – Domain Controller Security Policy – Open A/c Policy – Open
password policy: You will find Six Password Policies

1. Minimum Password length: This security setting determines the least number of characters that a
password for a user account may contain. You can set a value of between 1 and 14 characters, or you
can establish that no password is required by setting the number of characters to 0.
Default: 7 on Domain Controller
0 on stand-alone Server

2. Password must meet complexity requirement: If this policy is enabled, passwords must meet the
following minimum requirements when they are changed or created:
1 Password should not contain significant portions of the user's account name or full name
2 Password should be at least six characters in length
3 Password should Contain characters from three of the following four categories:
a) English uppercase characters (A through Z)
b) English lowercase characters (a through z)
c) Base 10 digits (0 through 9)
d) Non-alphabetic characters (for example, !, $, #, %)
Default: Enabled on domain controllers.
Disabled on stand-alone servers.

3. Minimum Password Age: This security setting determines the period of time (in days) that a
password must be used before the user can change it. You can set a value between 1 and 998 days,
or you can allow changes immediately by setting the number of days to 0.
Default: 1 on Domain Controller
0 on stand-alone Server
[Note: Configure the minimum password age to be more than 0 if you want “Enforce password history” to be effective]

4. Maximum Password Age: This security setting determines the period of time (in days) that a
password can be used before the system requires the user to change it. You can set passwords to
expire after a number of days between 1 and 999, or you can specify that passwords never expire by
setting the number of days to 0. If the maximum password age is between 1 and 999 days, the
Minimum password age must be less than the maximum password age. If the maximum password
age is set to 0, the minimum password age can be any value between 0 and 998 days.

Default: 42 days

No comments:

Post a Comment

hi, users please post comments and queries about posts and blog ,enjoy the technology.