Do not allow password expiration time longer than required by policy
Vérifié avec Microsoft LAPS (legacy) 6.2 — mis à jour le 15 septembre 2026 Pris en charge sur : At least Microsoft Windows Vista or Windows Server 2003 family
Obsolète : ce paramètre appartient à l’ancien Microsoft LAPS, remplacé par Windows LAPS intégré à Windows. Équivalent Windows LAPS : N’autorisez pas le délai d’expiration du mot de passe plus longtemps que ce qui est requis par la stratégie.
Chemin dans la console GPO
Configuration ordinateur\Modèles d'administration\LAPS Registre
Software\Policies\Microsoft Services\AdmPwd - Nom de valeur :
-
PwdExpirationProtectionEnabled
MDM / Intune (CSP)
./Device/Vendor/MSFT/Policy/Config/ADMX_AdmPwd/POL_AdmPwd_DontAllowPwdExpirationBehindPolicy Documentation Microsoft Learn Données de correspondance : Microsoft Learn (CC BY 4.0)
Description
When you enable this setting, planned password expiration longer than password age dictated by "Password Settings" policy is NOT allowed. When such expiration is detected, password is changed immediately and password expiration is set according to policy. When you disable or not configure this setting, password expiration time may be longer than required by "Password Settings" policy.
Générateur d'exports
BETAConfigurez l'état, la portée et les options, puis générez les sorties .reg, PowerShell, Intune et SCCM — ou ajoutez le paramètre à une collection multi-paramètres.
Ces exports écrivent le registre — ce n'est pas une GPO managée. ⓘ
Fichier .reg
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Do not allow password expiration time longer than required by policy
; State: Enabled
; Supported on: At least Microsoft Windows Vista or Windows Server 2003 family
[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft Services\AdmPwd]
"PwdExpirationProtectionEnabled"=dword:00000001 Autres formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Do not allow password expiration time longer than required by policy
# State: Enabled
# Supported on: At least Microsoft Windows Vista or Windows Server 2003 family
$path = 'HKLM:\Software\Policies\Microsoft Services\AdmPwd'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'PwdExpirationProtectionEnabled' -Value 1 -Type DWord Intune XML
OMA-URI: ./Device/Vendor/MSFT/Policy/Config/ADMX_AdmPwd/POL_AdmPwd_DontAllowPwdExpirationBehindPolicy
Data type: String
Value:
<enabled/> Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Do not allow password expiration time longer than required by policy
# State: Enabled
# Supported on: At least Microsoft Windows Vista or Windows Server 2003 family
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft Services\AdmPwd' -Name 'PwdExpirationProtectionEnabled' -Expected 1 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Do not allow password expiration time longer than required by policy
# State: Enabled
# Supported on: At least Microsoft Windows Vista or Windows Server 2003 family
$path = 'HKLM:\Software\Policies\Microsoft Services\AdmPwd'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'PwdExpirationProtectionEnabled' -Value 1 -Type DWord Scripts SCCM
# Exported from gporais.com
# Policy: Do not allow password expiration time longer than required by policy
# State: Enabled
# Supported on: At least Microsoft Windows Vista or Windows Server 2003 family
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Do not allow password expiration time longer than required by policy
# State: Enabled
# Supported on: At least Microsoft Windows Vista or Windows Server 2003 family
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft Services\AdmPwd' -Name 'PwdExpirationProtectionEnabled' -Expected 1 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Do not allow password expiration time longer than required by policy
# State: Enabled
# Supported on: At least Microsoft Windows Vista or Windows Server 2003 family
$path = 'HKLM:\Software\Policies\Microsoft Services\AdmPwd'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'PwdExpirationProtectionEnabled' -Value 1 -Type DWord Vous construisez une collection multi-paramètres ? Ajoutez ce paramètre et générez des exports combinés (.reg, PowerShell, GPO).