Configure Fine-Grained Password Policies in Active Directory
Applies to: Windows Server 2025 / 2022 / 2019 / 2016 / 2012 R2 / 2012 Fine-Grained Password Policies (FGPPs) let you apply different password and account lockout settings to different sets of users in the same Active Directory domain. This is useful when one domain-wide policy is not enough, for example when privileged or service accounts need different controls from standard user accounts. FGPPs were introduced with Windows Server 2008. For currently supported Windows Server versions, Microsoft documents them for Windows Server 2025, 2022, 2019, and 2016, with a domain functional level of Windows Server 2012 or higher. In This Article 1. What Is a Fine-Grained Password Policy? 2. Requirements and Scope 3. Understand Precedence 4. Configure an FGPP with ADAC 5. Configure an FGPP with PowerShell 6. Verify…


