Hybrid Office - Password Expiration

%3CLINGO-SUB%20id%3D%22lingo-sub-1930512%22%20slang%3D%22en-US%22%3EHybrid%20Office%20-%20Password%20Expiration%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1930512%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20all%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20understand%20there%20is%20a%20new(ish)%20feature%20we%20can%20enable%20on%20our%20tenant%20to%20sync%20password%20expiration%3C%2FP%3E%3CP%3E%3CSPAN%3E%26nbsp%3BEnforceCloudPasswordPolicyForPasswordSyncedUsers%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EI%20just%20want%20to%20check%20the%20steps%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EEnable%20that%20policy%3C%2FSPAN%3E%3C%2FP%3E%3CP%20data-unlink%3D%22true%22%3EDo%20I%20need%20to%20set%26nbsp%3BSet-MsolPasswordPolicy%26nbsp%3B%26nbsp%3Bfor%20the%20tenant%20to%20match%20my%20onsite%20AD%3F%20Or%20does%20it%20get%20that%20password%20expiration%20value%20from%20my%20onsite%20AD%20from%20AD%20Connect%20per%20each%20user%3F%3C%2FP%3E%3CP%20data-unlink%3D%22true%22%3E%26nbsp%3B%3C%2FP%3E%3CP%20data-unlink%3D%22true%22%3EWe%20already%20are%20using%20password%20hash%20sync%20(and%20writeback).%20I%20believe%20I%20need%20to%20update%20all%20my%20existing%20users%20so%20they're%20updated%20but%20will%20this%20apply%20to%20new%20users%2C%20or%20do%20we%20need%20to%20manually%20update%20new%20users%20when%20connected%3F%3C%2FP%3E%3CP%20data-unlink%3D%22true%22%3E%26nbsp%3B%3C%2FP%3E%3CP%20data-unlink%3D%22true%22%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1930512%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAdmin%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1930791%22%20slang%3D%22en-US%22%3ERe%3A%20Hybrid%20Office%20-%20Password%20Expiration%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1930791%22%20slang%3D%22en-US%22%3EHi%2C%20have%20a%20look%20at%20this%20page%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fhybrid%2Fhow-to-connect-password-hash-synchronization%23enforcecloudpasswordpolicyforpasswordsyncedusers%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fhybrid%2Fhow-to-connect-password-hash-synchronization%23enforcecloudpasswordpolicyforpasswordsyncedusers%3C%2FA%3E%3C%2FLINGO-BODY%3E
Regular Contributor

Hi all,

 

I understand there is a new(ish) feature we can enable on our tenant to sync password expiration

 EnforceCloudPasswordPolicyForPasswordSyncedUsers

 

I just want to check the steps

 

Enable that policy

Do I need to set Set-MsolPasswordPolicy  for the tenant to match my onsite AD? Or does it get that password expiration value from my onsite AD from AD Connect per each user?

 

We already are using password hash sync (and writeback). I believe I need to update all my existing users so they're updated but will this apply to new users, or do we need to manually update new users when connected?

 

 

1 Reply