Fine grained password policy for domain admin accounts
hi, have windows server 2008 r2 forest/domain functional level in company. there few domain administrator accounts created administering domain account password never expires according external control people should changed. proposed define different minimal password length accounts example 10 since default domain policy defines minimal password length 7.
i can create new password settings object settings defined , apply it domain administrator accounts interested in how administrators change password if forget change password before it's expiration since not receive information password expire in x number of days on daily basis case "normal" domain account on client machines. use domain administrator account 90 % of time run as option consoles , opening powershell , third-party softwares in order to used require to be running under mine domain administrator account, , of course in establishing rdp connections myriad of servers.
my question how i/other domain admins change password if expires? rdp not give ctrl+alt+del option if right, run as option not prompt change password - both of these give info password expired have never tested done afterwards change password.
that not point vivian. there no possibility change password when run as option used. besides 2 persons have domain admin account - use built-in domain administrator account our security policy prohibits use of account not want violate policy.
hello,
correct, there time in admins life she/he must use rdp change password.
best regards
meinolf weber
mvp, mcp, mcts
microsoft mvp - directory services
my blog: http://blogs.msmvps.com/mweberdisclaimer: posting provided no warranties or guarantees , confers no rights.
twitter:
Windows Server > Directory Services
Comments
Post a Comment