Skip to content

Commit

Permalink
Update New-ADFineGrainedPasswordPolicy.md
Browse files Browse the repository at this point in the history
Updating 2025 version of the doc to reflect the changes made to the 2022 version of the doc.
  • Loading branch information
BRDPM committed Sep 18, 2024
1 parent fdb8d0e commit f0327d7
Showing 1 changed file with 4 additions and 7 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -71,13 +71,6 @@ PS C:\> New-ADFineGrainedPasswordPolicy -Instance $TemplatePSO -Name "AdminsPSO"

This example creates two new fine-grained password policy objects using a template object.

### Example 3: Create a fine-grained password policy with manual account unlock
```powershell
PS C:\> New-ADFineGrainedPasswordPolicy -Name "ManualUnlockPSO" -Precedence 500 -ComplexityEnabled $true -Description "Manual Unlock Password Policy" -DisplayName "Manual Unlock PSO" -LockoutDuration "00:00:00" -LockoutObservationWindow "00:00:00" -LockoutThreshold 3
```

This command creates a fine-grained password policy object named ManualUnlockPSO that would require manual unlock of accounts by the administrator.

## PARAMETERS

### -AuthType
Expand Down Expand Up @@ -275,6 +268,10 @@ The LDAP display name (**ldapDisplayName**) of this property is **msDS-lockoutOb
The lockout observation window must be smaller than or equal to the lockout duration for a password policy.
Use the *LockoutDuration* parameter to set the lockout duration time.

[!NOTE]
Setting the lockout observation window to 0 effectively means that the window is too short to
observe more than one password attempt, therefore the account will never be locked out.

Specify the time interval in the following format:

`D:H:M:S.F`
Expand Down

0 comments on commit f0327d7

Please sign in to comment.