Applying fine-grained password and account lockout policies
Active Directory comes with a built-in password policy. Admins can configure stricter password policies and account lockout policies. This way, privileged accounts, such as members of the Domain Admins group, can be configured with more secure password and account lockout settings. This recipe shows how.
Getting ready
To apply fine-grained password and account lockout policies, sign in to a domain controller or a member server and/or device with the Remote Server Administration Tools (RSAT) for Active Directory Domain Services installed.
Sign in with an account that is a member of the Domain Admins group, or with an account that is delegated to manage fine-grained password and account lockout policies in the domain.
Fine-grained password and account lockout policies require the Windows Server 2008 Domain Functional Level (DFL), or a higher version of the DFL.
How to do it...
This recipe shares two ways to...