Skip to main content
AD Academy
Day-to-day administration of AD
Beginner12 minLast updated: Topic 3 of 4

Password policy and Fine-Grained Password Policy

Default Domain Policy, account lockout and PSO for special groups.

Not read

What you will learn here

  • Where the password policy lives
  • How account lockout works
  • When you need a PSO (Fine-Grained)

Worth reading first:NTFS permissions vs Share permissions

The domain's password policy is set in the Default Policy and applies to all users. If a stricter policy is needed for a certain group (e.g. Admins) — a PSO (Password Settings Object) is used.

Get-ADDefaultDomainPasswordPolicy

New-ADFineGrainedPasswordPolicy -Name "PSO-Admins" -Precedence 10 `
  -MinPasswordLength 20 -LockoutThreshold 5 `
  -LockoutDuration "00:30:00" -ComplexityEnabled $true
Add-ADFineGrainedPasswordPolicySubject -Identity "PSO-Admins" -Subjects "Domain Admins"
powershell
Architecture and Theory — Under the Hood

The domain password policy comes from the Default Policy at the domain level only. For a different policy for a specific group, use Fine-Grained Password Policy (PSO).

  • Account Lockout Threshold protects against Brute Force but allows DoS against users.
  • PSO (Fine-Grained Password Policy) applies to a user or group, and when there are several — the determining one is the lowest Precedence, not the strictest.
Practical Configuration (PowerShell / GUI)
Get-ADDefaultDomainPasswordPolicy
New-ADFineGrainedPasswordPolicy -Name "Admins-PSO" -Precedence 10 -MinPasswordLength 16 -LockoutThreshold 5
Add-ADFineGrainedPasswordPolicySubject "Admins-PSO" -Subjects "Domain Admins"
Search-ADAccount -LockedOut
powershell
Troubleshooting and Resolution
  • Repeated lockouts — usually an old password in a service/phone/Mapped Drive. Look for Event 4740 and the Caller Computer Name.

Check yourself

What does PSO allow?

Was this page helpful?