Managing Fine Grained Password Policies…

Analysis
Sep 18, 20072 mins

One of my co-workers recently asked me if there was a better method for managing Fine Grained Password polices in Windows Server 2008.  Basically, he came across Microsoft’s (pretty good) step-by-step for using this feature on TechNet – Link.  Upon reading the first step, he quickly realized that managing this feature was going to suck. 

Why Microsoft!  Like BitLocker, you yet again taunt us with a really cool feature.  But, yet again the management of the feature is from the bowls of suckiness.  I’m actually biting my tongue here.  Yes, if I really wanted to… I could fire up adsiedit and ldifde to complete the management task at hand.  But, I have to ask the question, what about the IT Pros that don’t dabble with those tools on a daily basis?  You know, the ones managing your products.  Forgive me for getting riled up.  But, you did this to me with BitLocker and there is yet again a cool feature that isn’t fully baked.  I shouldn’t have to go through a multi-step process involving several different tools just to manage one feature.  Give me a GUI that is driven by a set of PowerShell cmdlets (click or command it).  Errr… like Quest did.

Anyhow, I’m done.  My reply to my co-worker was to use either the PasswordSettingsObject cmdlets from Quest or the PowerGUI snap-in which uses those cmdlets – https://powergui.org/entry.jspa?externalID=882&categoryID=46.

For all of today’s Microsoft news, visit the Microsoft Subnet.