Implementing Password Policies on a Windows Server 2008 Domain

Loki Morgan
Are you ready to impose annoying password changes on your users? Well, it has gotten even easier in Windows Server 2008! Say goodbye to setting the default domain policy and say hello to multiple password and account lock out policies. In a Windows Server 2008 Domain, you use a Password Settings Container (PSC) which stores your Password Settings Objects (PSOs) for the domain.

How many unique password policies do you want? Take advantage of the new feature but don't go crazy. Consider the different groups in your organization and break them down into groups that logically need different policies. It is recommended that you keep the number of PSOs between three and ten.

Here is one example:

- Service Account Policy that doesn't force password changes but has a high minimum for password length

- Average Joe Policy that ensures passwords gets changed and meet minimum complexity requirements

- Super Awesome Administrator Policy that is more strict than your Average Joe Policy

- Super Annoying People Policy that forces password changes every 2 days and requires a minimum password length of 100

PSOs are not applied to OUs, instead they are applied to global security groups. You create your global security groups within Active Directory Users and Computers. Don't forget to add your users into their respective security groups. If you don't want everyone changing their password on the same day you can stagger the time between adding users to their security group. Although you can have multipurpose security groups, I recommend you limit these to the enforcement of the password policies only.

Once you have your security groups created and populated you can start by creating your first PSO. This can be done using ADSI Edit or ldifde. You can find step-by-step instructions at http://technet.microsoft.com/en-us/library/cc754461.aspx.

The next step is to apply the PSO to the Global Security Group. This can be done within Active Directory Users and Computers or with ldifde. You can find step-by-step instructions at http://technet.microsoft.com/en-us/library/cc731589.aspx

You can delete PSOs if you wish. You can also adjust who is affected by the password policy by adding and deleting users from the linked global security group. I find these policies very easy to maintain.

In my environment I was able to create the policies and implement them in one day. This is one new aspect of my Windows Server 2008 domain that makes me very happy. It allows multiple levels of security which also makes my end users and the auditors happy.

Source:

Microsoft, Inc.

http://technet.microsoft.com/en-us/library/cc770842.aspx

Published by Loki Morgan - Featured Contributor in Technology

Loki Morgan is a Microsoft Certified Professional with over ten years experience in the Information Technology field including technical writing. Morgan has published online content with a focus on compute...  View profile

4 Comments

Post a Comment
  • Sally Robertson MA, MA, LPC4/13/2009

    Holy Cow, I am glad I do not have to deal with this! But I know it is very important.

  • Nikki3/30/2009

    WE're looking into this right now. Thanks for the primer :)

  • Elizabeth Woodruff3/27/2009

    Wow. Good stuff. And really well written!

  • L.L. Woodard3/27/2009

    This topic is out of my realm of experience, but because it is so well-written, if I wanted to, I bet I could follow your tips.

Displaying Comments

To comment, please sign in to your Yahoo! account, or sign up for a new account.