Emergency server help: get in touch

Fine-Grained Password Policy (PSO) in Active Directory: 2026 Setup

How to create Password Settings Objects with New-ADFineGrainedPasswordPolicy or the Administrative Center, apply stricter or looser rules to specific groups, control precedence, and confirm which policy a user actually receives.

Published Updated 5 min read

The Default Domain Policy sets one password and lockout policy for every user in the domain, which is rarely what you want: privileged accounts should have longer passwords and faster lockouts, while a handful of service accounts may need exemptions from expiry. Fine-grained password policies, stored as Password Settings Objects (PSOs) in the Password Settings Container, apply different rules to specific users or global security groups without touching the domain-wide defaults. They require a domain functional level of Windows Server 2008 or higher, which every Windows Server 2019, 2022 and 2025 domain meets.

Short answer: Create a PSO with New-ADFineGrainedPasswordPolicy -Name "Admins-PSO" -Precedence 10 -MinPasswordLength 16 -MaxPasswordAge 90.00:00:00 -LockoutThreshold 5 -ComplexityEnabled $true, apply it to a global group with Add-ADFineGrainedPasswordPolicySubject -Identity Admins-PSO -Subjects "Tier0-Admins", and check the result on a user with Get-ADUserResultantPasswordPolicy jsmith. The PSO with the lowest precedence number wins when a user is in several groups, and a PSO linked directly to a user always beats one linked through a group.

Plan the policies before creating them

PSOs apply only to users and global security groups, never to OUs, universal groups or computers. Decide on a small set, typically three:

  • Privileged accounts: length 16 or more, 90-day maximum age, five-attempt lockout for 30 minutes, complexity on
  • Standard users: usually left on the domain default, or a PSO that matches the default with a lower precedence so future changes are explicit
  • Service accounts: long passwords, no expiry (-MaxPasswordAge 0 is not valid; use -PasswordNeverExpires on the account instead and a PSO for length), lockout disabled to avoid a mis-typed password taking down an application

Precedence is an integer; lower wins. Leave gaps (10, 20, 30) so you can insert policies later. Also check the domain policy first, because PSO lockout settings take over completely for their subjects, including observation window and duration:

Get-ADDefaultDomainPasswordPolicy

Create and apply a PSO with PowerShell

New-ADFineGrainedPasswordPolicy -Name "Tier0-Admins-PSO" -Precedence 10 `
  -ComplexityEnabled $true -MinPasswordLength 16 -PasswordHistoryCount 24 `
  -MinPasswordAge 1.00:00:00 -MaxPasswordAge 90.00:00:00 `
  -LockoutThreshold 5 -LockoutDuration 0.00:30:00 -LockoutObservationWindow 0.00:30:00 `
  -ReversibleEncryptionEnabled $false -ProtectedFromAccidentalDeletion $true

Add-ADFineGrainedPasswordPolicySubject -Identity "Tier0-Admins-PSO" -Subjects "Tier0-Admins","Domain Admins"

Timespans use the days.hours:minutes:seconds format. For a service account policy:

New-ADFineGrainedPasswordPolicy -Name "ServiceAccounts-PSO" -Precedence 20 `
  -ComplexityEnabled $true -MinPasswordLength 25 -PasswordHistoryCount 5 `
  -MinPasswordAge 0 -MaxPasswordAge 365.00:00:00 -LockoutThreshold 0
Add-ADFineGrainedPasswordPolicySubject -Identity "ServiceAccounts-PSO" -Subjects "SVC-Accounts"

The same objects can be created in the Active Directory Administrative Center: open the domain, go to System » Password Settings Container, and choose New » Password Settings. The form exposes every attribute and a “Directly Applies To” list for subjects. In Active Directory Users and Computers, PSOs are only visible with View » Advanced Features enabled, under System » Password Settings Container, and editing them there requires the Attribute Editor.

Check what a user actually gets

Because a user can be in several groups, the effective policy is not always obvious:

Get-ADUserResultantPasswordPolicy -Identity jsmith
Get-ADFineGrainedPasswordPolicy -Filter * | Select-Object Name, Precedence, AppliesTo
Get-ADUser jsmith -Properties msDS-ResultantPSO | Select-Object msDS-ResultantPSO

If the first command returns nothing, the user falls under the Default Domain Policy. Membership changes take effect immediately for new password attempts, but a user who is already logged on is not forced to change anything until their current password reaches the new maximum age. To force an immediate change for a group, set -ChangePasswordAtLogon $true with Set-ADUser. Note that Windows LAPS-managed local accounts are not affected by PSOs; their rules come from the LAPS policy described in set up Windows LAPS.

Verify and avoid the common trap

Test with a user in the group: reset the password to something short and expect “The password does not meet the length, complexity or history requirements”. Then check the lockout behaviour by entering a wrong password the threshold number of times and confirming Event ID 4740 on the PDC emulator, as covered in find the source of AD account lockouts. The most common mistake is applying a PSO to a universal or domain local group; the cmdlet accepts it silently in some versions but the policy never applies, and Get-ADUserResultantPasswordPolicy will show the domain default. Keep subjects as global groups and review AppliesTo quarterly.

Fine-grained password policy at a glance

Fine-Grained Password Policy summary card: Create a PSO with New-ADFineGrainedPasswordPolicy -Name "Admins-PSO" -Precedence 10 -MinPasswordLength 16…
In short: Create a PSO with New-ADFineGrainedPasswordPolicy -Name “Admins-PSO” -Precedence 10 -MinPasswordLength 16 -MaxPasswordAge 90.00:00:00 -LockoutThreshold 5 -ComplexityEnabled $true, apply it to a global group with…

Official documentation: Active Directory Domain Services docs, Windows Server documentation.

Related guides: Set up Windows LAPS on Windows Server 2025 and Windows 11 · Block USB storage devices with Group Policy and Intune · Fix “Invalid Signature Detected: Check Secure Boot Policy”.

Frequently asked questions

Does a fine-grained password policy override the Default Domain Policy for lockouts as well?

Yes; a PSO defines the complete set of password and lockout settings for its subjects, so if you leave the lockout values at defaults in the PSO, those defaults apply rather than the domain policy’s values.

How long does it take for a new PSO to apply to users?

It applies as soon as the PSO and the group membership have replicated to the DC the user authenticates against, typically under 15 minutes; existing passwords are not invalidated, only checked against the new rules at the next change or expiry.

Can I undo a PSO or remove a user from it?

Yes; remove subjects with Remove-ADFineGrainedPasswordPolicySubject or delete the PSO after clearing its accidental-deletion protection, and affected users immediately revert to the next applicable PSO or the domain default.

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.