Hi,
Our IS department will be implementing a password GPO in response to a security audit. Some users have ‘password never expires’ flag enabled. Some do not.
GPO will set the expiration date, minimum length, password history, account lockout and various other settings.
My concern is that the password expiration will immediately take place for the users. Here are my proposed steps to aovid this(using a third party tool):
1.Uncheck Password Never Expires field for all user accounts.
2.Reset pwdlastset value to 0. This starts off everyone at Day Zero with their current password.
3. Enable the password GPO.
Has anyone done something similar to the above? If yes, let me know if these steps are sufficient enoguh to get the job done.
Thanks in advance.