2012 R2 AD Password Policy

Our GPO sets 120 days password expiration. After we create an AD account, the password expires after 120 days. But some people didn't do their first logon during that period of time and we have to reset their passwords manually. Is it possible to set the policy as "after first logon, password will expire in 120 days"?

Thanks.

YHD

July 1st, 2015 11:47am

Hi,
 
As far as I know, we dont have such an policy which can function like after first logon, password will expire.
 
The password expiration date, by default, is calculated based on the sum of pwdLastSet and maxPwdAge attributes of the user in the Active Directory.
 

Regards,

Eth

Free Windows Admin Tool Kit Click here and download it now
July 2nd, 2015 3:01am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics