question relating to max password age for mobile users
For CTPAT compliance, I have to enable the maximum password age group policy setting. The path to the password settings is the following: Computer Configuration->Windows Settings->Security Settings->Account Policies->Password Policy I have about 40 mobile laptop salesmen who login with cached domain credentials, and are rarely at a location where they could communicate with one of our Server 2003 domain controllers. We have a single forest Server 2003 domain.How will the 'maximum password age' setting be applied to them out in the field? Let's say, I set the max password age to 90 days in GP, and then they go to one of our warehouses and login and get the updated group policy setting. Does this mean that on the 90th day from that one, when they attempt login, they will be prompted to change their password, even if they are not domain connected? Or, will they only get prompted the first time they are domain connected following the 90th day? I don't want to create the situation where they are out in the field somewhere, and boot up their laptop on day 90 , and go to logon, and they get prompted to change their password, but can't becuase they don't have domain connectivity, and thus are locked out of their machines.-jamie-
January 11th, 2010 6:24pm

Can somebody from Microsoft please comment on this, or is this question in the wrong newsgroup?
Free Windows Admin Tool Kit Click here and download it now
January 13th, 2010 9:24pm

Hello, Thank you for your post here. From the description, you want to know whether the password change notification will be shown if the user is logged onto the system with cached credentials. In Windows when your password is 14 days (by default) from expiration, you receive a Password Change Notification when logging on requesting you to change your password. The determination process to check whether the account password is set to expire and when the account will expire counts on the LDAP search in the AD. In the other word, if you logon with cached credentials, the password change notification will never show up. 14 Day Password Change Notification Cannot Be Changed http://support.microsoft.com/kb/135403 How Long Until My Password Expires? http://msdn.microsoft.com/en-us/library/ms974598.aspx If you have any questions or concerns, please do not hesitate to let me know.
January 19th, 2010 11:17am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics