

Maximum password age dictates the amount of days a password can be used before the user is forced to change it. The setting is applied to all domain computers and users. Password Expiration can be configured using the Maximum Password Age setting within the Default Domain Policy in the Group Policy Management Console. This article looks at what can be achieved using the native Active Directory (AD) Group Policy settings, including key capabilities that increase password security while balancing the user experience. With a sound policy in place, users will need to follow the composition requirements when changing or resetting their passwords.īut, what makes a password policy secure? There isn’t a shortage of regulatory and standard bodies that have weighed on this very topic. The two use cases are inherently tied to an organization’s domain password policy which traditionally encompass password complexity, length, and change frequency requirements. A user will perform a password change when they remember their existing password, and a password reset when they have forgotten it. Password change and password reset are terms that are often used interchangeably.
