Try our new Certificate Revocation List Check Tool
CRLcheck.exe is a tool developed to verify digital signatures of executable files. It collects files from known paths on your client, checks their signature, and checks Certificate Revocation Lists (CRL) and OCSP download. This helps avoid delays in launching files.
Category published:  GPO | Gruppenrichtlinien Microsoft Server OS Server 2008 R2 Server 2012 R2 Server 2016 W10   Click on the Category button to get more articles regarding that product.

Fine grained Password Policy on 2012R2 made easy with ADAC

Posted by admin on 08.07.2015

ADAC = NOT Deutscher Pannendienst 😉

Fine grained Password Policy in 2013 R2 Domain Active Directory, Error 4625 event

Sometimes you need accounts TO None expire or not getting Locked out. We all now it’s stupid in security terms but if the software has a bug and locks the account you have to hurry. Search on ALL of the Domain Controller for event 4625. There you should see the client who does it. There also lockout/whoislocked scripts which does that. (Account locked)

The regular Domain password policy is here:

But we want a second one with different settings and only for a few users in a security group

New way with ADAC on 2012R2

Old way with ADSIEDT.MSC

Make a new ADS group: sg_gpo_password_policy_bsb_non_locked and make the accounts which should have special password policy member of that group “Only user accounts”


Go to PASSSWORD Settings Container

Choose “Directly applies to” and make sure you choose the correct Security Group you made for this.

Under cmd on DC do a:

Repadmin /syncall

Its finished and working


 Category published:  GPO | Gruppenrichtlinien Microsoft Server OS Server 2008 R2 Server 2012 R2 Server 2016 W10   Click on the Category button to get more articles regarding that product.