Password expiration

BenBa 41 Reputation points
2023-06-19T13:04:11.07+00:00

Our on prem AD domain is set to have users passwords expire after 90 days. A percentage of our users are not being forced to change their passwords. We sync our on-prem AD to AAD. When looking at the synced profiles I noticed that these users that are not being prompted to change their passwords have an AAD attribute "Password policies" set to "DisablePasswordExpiration". Where would that be coming from? All these users are in the same OU with the same GPO but yet they are not being asked to change their passwords. The check box in ADUC for "Password Never Expires" is not selected.

Any insight would be appreciated.

-Ben

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Windows for business | Windows Server | Devices and deployment | Configure application groups
{count} votes

2 answers

Sort by: Most helpful
  1. Andy David - MVP 157.8K Reputation points MVP Volunteer Moderator
    2023-06-19T13:16:24.0433333+00:00

  2. Marilee Turscak-MSFT 37,206 Reputation points Microsoft Employee Moderator
    2023-06-19T21:43:51.3166667+00:00

    @BenBa ,

    In response to your second question about enforcing inheritance, you should be able to configure this in the directory system agent under Advanced features > View > Check "Include inheritable permissions" as described here.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.