Glossary
Fine-grained password policy
A fine-grained password policy (PSO) applies different password and lockout rules to specific AD users or groups than the domain default policy.
By default, an Active Directory domain has a single password and lockout policy, set in the Default Domain Policy GPO. Fine-grained password policies, available since Windows Server 2008, are stored as Password Settings Objects (PSOs) in the Password Settings Container. Each PSO defines length, complexity, history, age and lockout settings, and is applied directly to users or global security groups; when several apply, the one with the lowest precedence value wins. PSOs are managed with Active Directory Administrative Center or PowerShell, not with Group Policy.
It matters because different accounts face different risks. Privileged administrators and service accounts that cannot yet move to gMSA deserve much longer minimum lengths — for example 20 characters or more — than the baseline most users can reasonably manage. Apply PSOs to groups rather than individuals so policy follows role, check the resultant policy with Get-ADUserResultantPasswordPolicy, and combine length requirements with banned and breached password checks rather than forced periodic rotation.
See Password policy that works and Service account hardening.