Password policy & userAccountControl ?
There is a security audit in a company that states a large amount of users that are allowed to use weak/zero passwords. The domain policy setting says that weak/zero password isnt allowed. I have domain controllers with Windows 2003 SP1. After looking at the "weak/zero password user" it seems that it is not able to make a weak password by themself? But an admin can do it by resetting the password. Can anyone tell me which user attribute to look for to fix this problem? Thanks.
RE: Password policy & userAccountControl ?
You can try to remove the non-expiring flag for all users. You should also make sure that users change their password on a regular basis through the domain GPO and also check your password policy is proper and appropriate to the org. You need to also check your account lockout policy too.