# Fine-Grained Password Policy (PSO) in Active Directory: 2026 Setup

Source: https://srvscripts.com/guides/fine-grained-password-policy-pso/
Updated: 2026-10-06
Publisher: srvScripts (https://srvscripts.com/)

In short: Create a PSO with New-ADFineGrainedPasswordPolicy -Name “Admins-PSO” -Precedence 10 -MinPasswordLength 16 -MaxPasswordAge 90.00:00:00 -LockoutThreshold 5 -ComplexityEnabled $true, apply it to a global group with…

The Default Domain Policy sets one password and lockout policy for every user in the domain, which is rarely what you want: privileged accounts should have longer passwords and faster lockouts, while a handful of service accounts may need exemptions from expiry. Fine-grained password policies, stored as Password Settings Objects (PSOs) in the Password Settings Container, apply different rules to specific users or global security groups without touching the domain-wide defaults. They require a domain functional level of Windows Server 2008 or higher, which every Windows Server 2019, 2022 and 2025 domain meets.

**Short answer:** Create a PSO with `New-ADFineGrainedPasswordPolicy -Name "Admins-PSO" -Precedence 10 -MinPasswordLength 16 -MaxPasswordAge 90.00:00:00 -LockoutThreshold 5 -ComplexityEnabled $true`, apply it to a global group with `Add-ADFineGrainedPasswordPolicySubject -Identity Admins-PSO -Subjects "Tier0-Admins"`, and check the result on a user with `Get-ADUserResultantPasswordPolicy jsmith`. The PSO with the lowest precedence number wins when a user is in several groups, and a PSO linked directly to a user always beats one linked through a group.

## Plan the policies before creating them

PSOs apply only to users and global security groups, never to OUs, universal groups or computers. Decide on a small set, typically three:

- Privileged accounts: length 16 or more, 90-day maximum age, five-attempt lockout for 30 minutes, complexity on

- Standard users: usually left on the domain default, or a PSO that matches the default with a lower precedence so future changes are explicit

- Service accounts: long passwords, no expiry (`-MaxPasswordAge 0` is not valid; use `-PasswordNeverExpires` on the account instead and a PSO for length), lockout disabled to avoid a mis-typed password taking down an application

Precedence is an integer; lower wins. Leave gaps (10, 20, 30) so you can insert policies later. Also check the domain policy first, because PSO lockout settings take over completely for their subjects, including observation window and duration:

```
Get-ADDefaultDomainPasswordPolicy
```

## Create and apply a PSO with PowerShell

```
New-ADFineGrainedPasswordPolicy -Name "Tier0-Admins-PSO" -Precedence 10 `
  -ComplexityEnabled $true -MinPasswordLength 16 -PasswordHistoryCount 24 `
  -MinPasswordAge 1.00:00:00 -MaxPasswordAge 90.00:00:00 `
  -LockoutThreshold 5 -LockoutDuration 0.00:30:00 -LockoutObservationWindow 0.00:30:00 `
  -ReversibleEncryptionEnabled $false -ProtectedFromAccidentalDeletion $true

Add-ADFineGrainedPasswordPolicySubject -Identity "Tier0-Admins-PSO" -Subjects "Tier0-Admins","Domain Admins"
```

Timespans use the `days.hours:minutes:seconds` format. For a service account policy:

```
New-ADFineGrainedPasswordPolicy -Name "ServiceAccounts-PSO" -Precedence 20 `
  -ComplexityEnabled $true -MinPasswordLength 25 -PasswordHistoryCount 5 `
  -MinPasswordAge 0 -MaxPasswordAge 365.00:00:00 -LockoutThreshold 0
Add-ADFineGrainedPasswordPolicySubject -Identity "ServiceAccounts-PSO" -Subjects "SVC-Accounts"
```

The same objects can be created in the Active Directory Administrative Center: open the domain, go to System » Password Settings Container, and choose New » Password Settings. The form exposes every attribute and a “Directly Applies To” list for subjects. In Active Directory Users and Computers, PSOs are only visible with View » Advanced Features enabled, under System » Password Settings Container, and editing them there requires the Attribute Editor.

## Check what a user actually gets

Because a user can be in several groups, the effective policy is not always obvious:

```
Get-ADUserResultantPasswordPolicy -Identity jsmith
Get-ADFineGrainedPasswordPolicy -Filter * | Select-Object Name, Precedence, AppliesTo
Get-ADUser jsmith -Properties msDS-ResultantPSO | Select-Object msDS-ResultantPSO
```

If the first command returns nothing, the user falls under the Default Domain Policy. Membership changes take effect immediately for new password attempts, but a user who is already logged on is not forced to change anything until their current password reaches the new maximum age. To force an immediate change for a group, set `-ChangePasswordAtLogon $true` with `Set-ADUser`. Note that Windows LAPS-managed local accounts are not affected by PSOs; their rules come from the LAPS policy described in [set up Windows LAPS](/guides/windows-laps-setup/).

## Verify and avoid the common trap

Test with a user in the group: reset the password to something short and expect “The password does not meet the length, complexity or history requirements”. Then check the lockout behaviour by entering a wrong password the threshold number of times and confirming Event ID 4740 on the PDC emulator, as covered in [find the source of AD account lockouts](/guides/ad-account-lockout-source-event-4740/). The most common mistake is applying a PSO to a universal or domain local group; the cmdlet accepts it silently in some versions but the policy never applies, and `Get-ADUserResultantPasswordPolicy` will show the domain default. Keep subjects as global groups and review `AppliesTo` quarterly.

## Fine-grained password policy at a glance

**Official documentation:** [Active Directory Domain Services docs](https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/active-directory-domain-services), [Windows Server documentation](https://learn.microsoft.com/en-us/windows-server/).

**Related guides:** [Set up Windows LAPS on Windows Server 2025 and Windows 11](https://srvscripts.com/guides/windows-laps-setup/) · [Block USB storage devices with Group Policy and Intune](https://srvscripts.com/guides/block-usb-storage-group-policy-intune/) · [Fix “Invalid Signature Detected: Check Secure Boot Policy”](https://srvscripts.com/guides/invalid-signature-detected-secure-boot/).

## Frequently asked questions

### Does a fine-grained password policy override the Default Domain Policy for lockouts as well?

Yes; a PSO defines the complete set of password and lockout settings for its subjects, so if you leave the lockout values at defaults in the PSO, those defaults apply rather than the domain policy’s values.

### How long does it take for a new PSO to apply to users?

It applies as soon as the PSO and the group membership have replicated to the DC the user authenticates against, typically under 15 minutes; existing passwords are not invalidated, only checked against the new rules at the next change or expiry.

### Can I undo a PSO or remove a user from it?

Yes; remove subjects with `Remove-ADFineGrainedPasswordPolicySubject` or delete the PSO after clearing its accidental-deletion protection, and affected users immediately revert to the next applicable PSO or the domain default.
