When you create a group policy object in a domain for passwords I know it applies to all users in the domain.
Can you create another group policy in an organizational unit of the domain to tighten requirements only for that specific OU or can they only be set at the domain level?
I seem to recall somewhere that password policies set at the domain level will always override password policies set at the OU level.