Lets particular users or global security groups (but not OUs) have their own password and lockout rules, overriding the domain default. The settings live in a Password Settings Object.
Also called FGPP.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Fine-grained password policy in context, with comparison tables and the common traps.
Terms in this definition
- AGDLP
Nesting pattern: users go into global groups, which go into domain local groups, which receive the permissions. AGUDLP adds universal groups for forests with several domains.
- Domain
A way of grouping workspaces by area of the business, in support of a data mesh approach. Items take on their workspace's domain, letting you filter the OneLake catalog by it, and certain tenant settings can be passed to domain admins; domains have no effect on access permissions.
- PSO
Password settings object. Holds fine-grained lockout and password rules aimed at global groups or users; if several apply, the smallest precedence number takes effect.
Related terms
- Active Directory Administrative Center
Includes a viewer showing the PowerShell behind each action, fine-grained password policy management and Recycle Bin restores; a Windows Server console for Active Directory built on PowerShell.
- Password Settings Container
Each domain has this system container, which is where fine-grained password policy objects get created.