If the current policy on an NT domain says passwords can be 6 characters long, and that policy is then changed to 8 characters, does every password in the domain suddenly become invalid ? or is the increased number of characters enforced on the nextpassword change ?