Using item level targeting in GPO

8 Mar 2010

I need some help/advise regarding setting up domain passwords using GPO. I need the policy to set two different maximum days age depending on what OU the computer is in.

I am trying to get item-level targeting to work so that if computer 1 is in HR then set it to 90 days, if not in HR then 180 days.

I have set 180 days in 'Policies > Windows settings > Security settings > Password Policy

I have then added two registry entries for the 90 days & 180 days in 'Preferences > Windows settings > Registry > Registry Wizard Values > HKLM > SYSTEM > CurrentControl Set > Services > Netlogon > Parameters

Reg key = 'MaximumPasswordAge' replace REG_DWORD 90
Item level targeting 'computer in OU belongs to is HR'

When i RSOP the computer it shows the value of 180 which i set in the policy, so it looks like either reg key isn't being written, or the reg key is being overwritten for some reason.

Any help/guidence would be appreciated

Last edited:
It's been a while since I've looked at local password policy but I take it given this approach that this is a workgroup rather than a domain? Password policy usually has nothing to do with computer side GPOs
It's been a while since I've looked at local password policy but I take it given this approach that this is a workgroup rather than a domain? Password policy usually has nothing to do with computer side GPOs
He literally says he's setting up domain passwords via GPO and you head down the assumption this is a workgroup, which has neither domain passwords or "group" policies.

I wouldn't have an item level target for this. Just two GPOs, one set per OU.

Just FYI though. Password age is now a security no no. Should be set to 0 and passwords managed using alternative mechanisms like Hello
Last edited:
Top Bottom