Password policies only work from the domain level and are ignored at all other OU levels.

If you want this to be in effect, add that setting into the domain-level GPO, if you don't want it set for everyone in the organization, accept that you're going to have to do it manually (or with a script) on the user objects within the appropriate OU.



On 11/6/06, Sri <[EMAIL PROTECTED]> wrote:
Hi List,

    I am using AD on Win2k3 server.
    I have a requirement to disable the option "User must change password at next login" while adding a user to AD from AD Users & Computers console and enable " password never expires" checkbox.
    While adding a user to a container, " User must change password at next login" is checked defaultly.
To disable this option, the cmd line option "-pwdneverexpires yes" is working from AD machine's cmd prompt.
To do the same from AD U & C console, i created a group policy and set the max and min password ages in Account Settings --> password policies.
But still the option "User must change password at next login" is checked and not checking the "password never expires".

Pls help me in this.

Thanks in Advance.

Sri


Reply via email to