As far as I know the password complexity requirement is a domain wide setting. You cannot set different policies for groups of machines. And the reason it is a computer setting (I am assuming) is because the machines and what is on them are the assets, not the user. Another reason that it would be a computer setting is a user may cross domains (a boundary which may have a different password policy) to access a resource. I am sure someone can more elegantly put what I am thinking in my head, but that is what I got J

 

 

 

 


From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Kurt Hill
Sent: Monday, April 11, 2005 4:43 PM
To: ActiveDir@mail.activedir.org
Subject: [ActiveDir] Password complexity requirements

 

Can anyone explain why password complexity requirements are a computer, and not a User setting?  The scenario I envision for using password complexity requirements is for network admins (Users!!) who I want to force more complex passwords on, but general users (students) do not need this setting.  From what I can see, the way MS set it up, I would set password policy on student computers, and admin policy on admin computers, but that means that an admin can go to a student computer and pick a more convenient password!!  How does that pass for security??

 

Any ideas on that one?

 

Thanks,

Kurt

 

Reply via email to