Active Directory Schema Attribute: ms-DS-Password-Settings-Precedence
AD Schema Attributes » Active Directory Schema Attribute : ms-DS-Password-Settings-Precedence

What is the need for ms-DS-Password-Settings-Precedence attribute in Active Directory

When multiple password settings objects (PSOs) are applied to an object, this attribute specifies the precedence or order of priority in which the PSOs should be applied. Lower the value for a PSO, higher its precedence.

LDAP display name msDS-PasswordSettingsPrecedencep
CN ms-DS-Password-Settings-Precedence
Single or multi-valued Single-valued
Data type String(NT-Sec-Desc)
Attribute Id 1.2.840.113556.1.4.2023
Classes used in ms-DS-Group-Managed-Service-Account

For more details about this attribute, please refer to this MS document.

Did you know?

You can find out all password expired users, users whose passwords will expire soon, users whose passwords will never expire, etc., at just the click of a mouse button. In fact you can also manage and report on AD user accounts easily, without scripting.

Wondering how? Just give ADManager Plus a try.

This integrated AD, Office 365 and Exchange management software offers predefined features and reports to:

  • Find users with expired, soon-to-expire and never expiring passwords, and reset their passwords, right from the report.
  • Identify password unchanged users and users who have to change their passwords at the next logon.
  • Reset or change passwords of users in bulk, at once.
  • Know users' real last logon times, and the recently logged on users.
  • Find all locked out user accounts.
  • Unlock locked out user accounts in bulk, using CSV.
  • Automatically unlock all locked out accounts, periodically.
  • Generate detailed report on locked out user accounts, and unlock them on-the-fly, right from the report.
  • Delegate the task of password reset and unlocking locked out user accounts securely to help desk and even non-IT users.
  • View all the password expired and locked out user accounts in the domain in a customizable dashboard.

Download the free 30-day trial of ADManager Plus to explore all these features and more, in your environment at your convenience.

Script-free, automated AD management and reporting

ADManager Plus, an identity governance solution for Active Directory, Microsoft 365, and Google Workspace, offers features for automating the bulk creation and modification of user accounts via CSV files and intelligent templates. Generate and schedule more than 200 preconfigured reports on users; export them in CSV, PDF, HTML, XLSX, and CSVDE formats; and do even more.

Unravel end-to-end Active Directory management with ADManager Plus

  •  
  •  
  •  
  • By clicking 'Schedule a personalized demo' you agree to processing of personal data according to the Privacy Policy.
AD User Management / Reports
Active Directory Reporting
Active Directory Management
Related Products