Query Domain Password Policy
This password policy is configured by group policy and linked to the root of the domain.
Query domain password policy. Open the group policy management console 2. Recently i was asked how to retrieve a domain s account lockout policy and password policy with windows powershell. In fact when you update these policies with the group policy management console it is the role of the domain s pdc emulator to write the changes to.
Expand domains your domain then group policy objects. To view the password policy follow these steps. Back in 2003 i had written some powershell code to query group policy for the lockout policy of an active directory domain.
Typically and by default in a new ad domain the built in default domain policy gpo is used to set the active directory password policy as shown in the screenshot above. You can identify a domain by its distinguished name guid security identifier sid dns domain name or netbios name. Both are stored as attributes on each domain s domain naming context.
The get addefaultdomainpasswordpolicy cmdlet gets the default password policy for a domain. I ve been working with powershell since the version 1 0 days and i m still amazed that i find cmdlets that i didn t know existed.