The domain's password policy is set in the Default Policy and applies to all users. If a stricter policy is needed for a certain group (e.g. Admins) — a PSO (Password Settings Object) is used.
Get-ADDefaultDomainPasswordPolicy
New-ADFineGrainedPasswordPolicy -Name "PSO-Admins" -Precedence 10 `
-MinPasswordLength 20 -LockoutThreshold 5 `
-LockoutDuration "00:30:00" -ComplexityEnabled $true
Add-ADFineGrainedPasswordPolicySubject -Identity "PSO-Admins" -Subjects "Domain Admins"powershellArchitecture and Theory — Under the Hood
The domain password policy comes from the Default Policy at the domain level only. For a different policy for a specific group, use Fine-Grained Password Policy (PSO).
- Account Lockout Threshold protects against Brute Force but allows DoS against users.
- PSO (Fine-Grained Password Policy) applies to a user or group, and when there are several — the determining one is the lowest Precedence, not the strictest.
Practical Configuration (PowerShell / GUI)
Get-ADDefaultDomainPasswordPolicy
New-ADFineGrainedPasswordPolicy -Name "Admins-PSO" -Precedence 10 -MinPasswordLength 16 -LockoutThreshold 5
Add-ADFineGrainedPasswordPolicySubject "Admins-PSO" -Subjects "Domain Admins"
Search-ADAccount -LockedOutpowershellTroubleshooting and Resolution
- Repeated lockouts — usually an old password in a service/phone/Mapped Drive. Look for Event 4740 and the Caller Computer Name.