Domain Controller Password Policy
Open the group policy management console 2.
Domain controller password policy. This command gets the default domain password policy from current logged on user domain. Click local policies to edit the audit policy a user rights assignment or security options. Now navigate to computer configuration policies windows settings security settings account policies password policy.
The way the password policy works is that this gpo and the settings contained within this gpo configure the domain controllers dcs and the active directory databases located on them. To edit default domain policy settings you must have the domain administrator. Get the default domain password policy from the current local computer.
The domain controller the owner of fsmo s pdc emulator role manages the domain password policy. Domain controllers pull some security settings only from group policy objects linked to the root of the domain. There are two commands which check the password policy.
Do one of the following. Because domain controllers share the same account database for the domain certain security settings must be set uniformly on all domain controllers. Right click the default domain policy and click edit.
Net accounts checks local password policies on a server net accounts domain checks the domain password policy on a server domain policy always wins over a local policy. To open the domain controller security policy in the console tree locate grouppolicyobject computername policy click computer configuration click windows settings and then click security settings. Double click account policies to edit the password policy account lockout policy or kerberos policy.
If you create another gpo with different password settings and apply it to the specific ou its settings will be ignored. To view the password policy follow these steps. This password policy is configured by group policy and linked to the root of the domain.