Do not allow password expiration time longer than required by policy
Verified with Microsoft LAPS (legacy) 6.2 — updated on September 15, 2026 Supported on: At least Microsoft Windows Vista or Windows Server 2003 family
Deprecated: this setting belongs to the legacy Microsoft LAPS, replaced by Windows LAPS built into Windows. Windows LAPS equivalent: Do not allow password expiration time longer than required by policy.
Path in the GPO console
Computer Configuration\Administrative Templates\LAPS Registry
Software\Policies\Microsoft Services\AdmPwd - Value name:
-
PwdExpirationProtectionEnabled
MDM / Intune (CSP)
./Device/Vendor/MSFT/Policy/Config/ADMX_AdmPwd/POL_AdmPwd_DontAllowPwdExpirationBehindPolicy Microsoft Learn documentation Mapping data: Microsoft Learn (CC BY 4.0)
Description
When you enable this setting, planned password expiration longer than password age dictated by "Password Settings" policy is NOT allowed. When such expiration is detected, password is changed immediately and password expiration is set according to policy. When you disable or not configure this setting, password expiration time may be longer than required by "Password Settings" policy.
Export Builder
BETAConfigure the state, scope and options, then generate .reg, PowerShell, Intune and SCCM outputs — or add the setting to a multi-setting collection.
These exports write the registry — this is not a managed GPO. ⓘ
.reg file
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Do not allow password expiration time longer than required by policy
; State: Enabled
; Supported on: At least Microsoft Windows Vista or Windows Server 2003 family
[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft Services\AdmPwd]
"PwdExpirationProtectionEnabled"=dword:00000001 More formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Do not allow password expiration time longer than required by policy
# State: Enabled
# Supported on: At least Microsoft Windows Vista or Windows Server 2003 family
$path = 'HKLM:\Software\Policies\Microsoft Services\AdmPwd'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'PwdExpirationProtectionEnabled' -Value 1 -Type DWord Intune XML
OMA-URI: ./Device/Vendor/MSFT/Policy/Config/ADMX_AdmPwd/POL_AdmPwd_DontAllowPwdExpirationBehindPolicy
Data type: String
Value:
<enabled/> Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Do not allow password expiration time longer than required by policy
# State: Enabled
# Supported on: At least Microsoft Windows Vista or Windows Server 2003 family
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft Services\AdmPwd' -Name 'PwdExpirationProtectionEnabled' -Expected 1 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Do not allow password expiration time longer than required by policy
# State: Enabled
# Supported on: At least Microsoft Windows Vista or Windows Server 2003 family
$path = 'HKLM:\Software\Policies\Microsoft Services\AdmPwd'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'PwdExpirationProtectionEnabled' -Value 1 -Type DWord SCCM scripts
# Exported from gporais.com
# Policy: Do not allow password expiration time longer than required by policy
# State: Enabled
# Supported on: At least Microsoft Windows Vista or Windows Server 2003 family
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Do not allow password expiration time longer than required by policy
# State: Enabled
# Supported on: At least Microsoft Windows Vista or Windows Server 2003 family
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft Services\AdmPwd' -Name 'PwdExpirationProtectionEnabled' -Expected 1 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Do not allow password expiration time longer than required by policy
# State: Enabled
# Supported on: At least Microsoft Windows Vista or Windows Server 2003 family
$path = 'HKLM:\Software\Policies\Microsoft Services\AdmPwd'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'PwdExpirationProtectionEnabled' -Value 1 -Type DWord Building a multi-setting collection? Add this setting and generate combined .reg / PowerShell / GPO scripts.