Fine-grained password policy
As promised way back during our discussion of domain-level password policy, we are here to walk through the building of a fine-grained password policy. Most organizations do require specific password complexity for their users, but almost always by way of the default domain policy GPO, which means that the password complexity and expiration settings are exactly the same for everyone within the domain.
What if you have requirements to enable complexity on some user accounts but not on others? Perhaps you have sales personnel who travel constantly and requiring very strong and complex passwords makes a lot of sense for them. But let's say you also have a machine shop where users have to log into computers every day, but those computers never leave the office and the users never type in their credentials into any systems other than those physically secure devices.
Is it really necessary for those machine shop users to have the same level of password complexity...