How do I manage the password policy for the LOCAL accounts on cloud-azure joined machines?

iconoclast88 61 Reputation points
2024-07-30T18:55:26.7066667+00:00

We are trying to manage/set the policy for local accounts on workstations joined to azure cloud. (no on-prem domain or hybrid)

I followed this

https://www.anoopcnair.com/mdm-wins-over-gpo-group-policy-intune-policy/

and created this policy as well

https://howtomanagedevices.com/intune/2409/password-policies-using-intune/

But 24 hours later, the user signs into a local account (to manage local resources outside of 365)

and the local policy still displays the default 42 days, etc. I set it to 90 days, for example among other changes.

User's image

Windows 11
Windows 11
A Microsoft operating system designed for productivity, creativity, and ease of use.
9,916 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
5,207 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
22,142 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Rahul Jindal [MVP] 10,196 Reputation points MVP
    2024-07-30T19:10:09.42+00:00
    0 comments No comments

  2. ZhoumingDuan-MSFT 13,890 Reputation points Microsoft Vendor
    2024-07-31T01:59:18.5366667+00:00

    @iconoclast88, Thanks for posting in Q&A.

    For your issue, I have followed the link you provided to configure the password policy for the local account, in the Local Group Policy Editor of targeted device I met the same with you, however, based on my experience, Intune policy will just modify settings on the device via Windows CSP, it will not modify the GPO settings, so please check the policy status in Intune portal and go to the targeted device to check if there is some error in Event Viewer(Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider/Admin) and check the registry values(Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\Providers\9A96DE87-65BD-437E-B915-14B601DAE840\default\Device\DeviceLock, the value under Providers maybe different in different devices) were changed.

    User's image

    https://howtomanagedevices.com/intune/2409/password-policies-using-intune/

    Non-official, just for reference.

    If there are no errors in Event Viewer and the registry values are same as the policy's settings you configured in Intune, that means the policy applied successfully and you have settled Max password age value to 90.

    Hope this can help you.

    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.