Limitations
Fine-grained password policies have the following limitations:
- Fine-grained password policies can only be applied to users and global security groups. They can't be applied to OUs.
- By default, only domain admins/enterprise admins can set up/manage/delete fine-grained password policies. It is possible to delegate permission to other users if required.
- The minimum domain functional level is Windows Server 2008.
When you use fine-grained password policies, some objects may have multiple fine-grained password policies applied. However, only one password policy can be applied to an object at a given time. It is not possible to merge multiple policies either. So how do we know what is the winning policy? Or how can we enforce a policy? Let's find out the answers in the next section.