4.7 KiB
title, description, ms.assetid, ms.pagetype, ms.prod, ms.mktglfcycl, ms.sitesec, author
title | description | ms.assetid | ms.pagetype | ms.prod | ms.mktglfcycl | ms.sitesec | author |
---|---|---|---|---|---|---|---|
Interactive logon Prompt user to change password before expiration (Windows 10) | Describes the best practices, location, values, policy management and security considerations for the Interactive logon Prompt user to change password before expiration security policy setting. | 8fe94781-40f7-4fbe-8cfd-5e116e6833e9 | security | W10 | deploy | library | brianlic-msft |
Interactive logon: Prompt user to change password before expiration
Applies to
- Windows 10 Describes the best practices, location, values, policy management and security considerations for the Interactive logon: Prompt user to change password before expiration security policy setting.
Reference
The Interactive logon: Prompt user to change password before expiration policy setting determines how many days in advance users are warned that their passwords are about to expire. With this advance warning, the user has time to construct a password that is sufficiently strong.
Possible values
- A user-defined number of days from 0 through 999.
- Not defined.
Best practices
- Configure user passwords to expire periodically. Users will need warning that their passwords are going to expire, or they might inadvertently get locked out of the system. This could lead to confusion for users who access the network locally, or make it impossible for users who access the network through dial-up or virtual private network (VPN) connections to log on.
- Set Interactive logon: Prompt user to change password before expiration to 5 days. When their password expiration date is 5 or fewer days away, users will see a dialog box each time they log on to the domain.
- Do not set the value to 0, which results in displaying the password expiration warning every time the user logs on.
Location
Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options
Default values
The following table lists the actual and effective default values for this policy. Default values are also listed on the policy’s property page.
Server type or GPO | Default value |
---|---|
Default Domain Policy |
Not defined |
Default Domain Controller Policy |
Not defined |
Stand-Alone Server Default Settings |
14 days * |
DC Effective Default Settings |
14 days * |
Member Server Effective Default Settings |
14 days * |
Client Computer Effective Default Settings |
14 days * |