Click here to get back home

machine password expiration in the 2003 domain environment

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
machine password expiration in the 2003 domain environment Drew Govnyak 04-14-2008
Posted by Drew Govnyak on April 14, 2008, 10:57 am
Please log in for more thread options
Does anybody know the default Machine Account Password expiration in a
Windows 2003 domain in native mode? Just to clarify what I am looking for is
the machine password, not user.

Thanks




Posted by Roger Abell [MVP] on April 17, 2008, 10:17 am
Please log in for more thread options
> Does anybody know the default Machine Account Password expiration in a
> Windows 2003 domain in native mode? Just to clarify what I am looking for
> is the machine password, not user.
>
> Thanks

As far as I know there is no such thing for machine accounts.
In policy you can control whether machines change their password, and how
often,
but that is a behavior of the joined machine and is not a behavior required
by the
domain (i.e. if the machine does not do it on time there is not anything
forced onto
the machine by the domain).

Roger



Posted by Drew Govnyak on April 17, 2008, 10:34 am
Please log in for more thread options
You are wrong!

http://technet2.microsoft.com/windowsserver/en/library/8af78a8c-6e66-4420-9ee7-d82dd1c9e0c61033.mspx


>> Does anybody know the default Machine Account Password expiration in a
>> Windows 2003 domain in native mode? Just to clarify what I am looking for
>> is the machine password, not user.
>>
>> Thanks
>
> As far as I know there is no such thing for machine accounts.
> In policy you can control whether machines change their password, and how
> often,
> but that is a behavior of the joined machine and is not a behavior
> required by the
> domain (i.e. if the machine does not do it on time there is not anything
> forced onto
> the machine by the domain).
>
> Roger
>



Posted by Roger Abell [MVP] on April 17, 2008, 9:27 pm
Please log in for more thread options

> You are wrong!
>
>
http://technet2.microsoft.com/windowsserver/en/library/8af78a8c-6e66-4420-9ee7-d82dd1c9e0c61033.mspx
>
>

With all due respect Drew I do not believe that you read the short sentence
under
description in page of link you referenced.
The machine attempts to change its password with the frequence that is set
(30 day default).
As I had replied, that is a behavior of the joined machine. It is not a
required change imposed
by the domain with the domain expiring the account if it is not done within
that time.
Password expiration exists for user principals but as far as I have ever
known does not
exist for the passwords of machine join accounts.

Why are you asking?
Have you experience something that leads you to think machine account
password expiration is the cause ?

Roger


>>> Does anybody know the default Machine Account Password expiration in a
>>> Windows 2003 domain in native mode? Just to clarify what I am looking
>>> for is the machine password, not user.
>>>
>>> Thanks
>>
>> As far as I know there is no such thing for machine accounts.
>> In policy you can control whether machines change their password, and how
>> often,
>> but that is a behavior of the joined machine and is not a behavior
>> required by the
>> domain (i.e. if the machine does not do it on time there is not anything
>> forced onto
>> the machine by the domain).
>>
>> Roger
>>
>
>



Posted by kj [MVP SBS] on April 18, 2008, 4:40 pm
Please log in for more thread options

>
>> You are wrong!
>>
>>
http://technet2.microsoft.com/windowsserver/en/library/8af78a8c-6e66-4420-9ee7-d82dd1c9e0c61033.mspx
>>
>>
>
> With all due respect Drew I do not believe that you read the short
> sentence under
> description in page of link you referenced.
> The machine attempts to change its password with the frequence that is set
> (30 day default).
> As I had replied, that is a behavior of the joined machine. It is not a
> required change imposed
> by the domain with the domain expiring the account if it is not done
> within that time.
> Password expiration exists for user principals but as far as I have ever
> known does not
> exist for the passwords of machine join accounts.

That is my understanding as well. DC policy exists to even decline computer
password change attempts completly. However this can result in WS passwords
remaining at the intial value equal to the computername$. It can be helpfull
for a temporary measure in machine imaging though.


>
> Why are you asking?
> Have you experience something that leads you to think machine account
> password expiration is the cause ?
>
> Roger
>
>
>>>> Does anybody know the default Machine Account Password expiration in a
>>>> Windows 2003 domain in native mode? Just to clarify what I am looking
>>>> for is the machine password, not user.
>>>>
>>>> Thanks
>>>
>>> As far as I know there is no such thing for machine accounts.
>>> In policy you can control whether machines change their password, and
>>> how often,
>>> but that is a behavior of the joined machine and is not a behavior
>>> required by the
>>> domain (i.e. if the machine does not do it on time there is not anything
>>> forced onto
>>> the machine by the domain).
>>>
>>> Roger
>>>
>>
>>
>
>



Similar ThreadsPosted
Windows Vista Group Policies in a Server 2003 SP1 Domain environment May 11, 2007, 9:21 am
Password expiration April 26, 2008, 4:41 am
server2008 password expiration disabled? February 28, 2008, 7:00 pm
Certs in non-domain environment: January 24, 2008, 12:51 pm
Viewing CMOS\BIOS settings in MS Server 2003 GUI environment June 3, 2006, 3:14 am
Windows 2003 domain password policy September 26, 2006, 9:53 pm
Maximum machine account password age March 14, 2006, 6:24 am
Changing local admin password on a set of machine in an ad network ? June 6, 2005, 1:28 pm
Web applications cannot connect to SQL Server on new Windows 2003 R2 machine June 28, 2008, 4:16 pm
setting up 2-Tier CA Environment July 14, 2005, 3:36 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap