AD-PWDPOL-02 - Password maximum age should be retrievable
Overviewโ
Maximum password age is a critical security control that forces users to change their passwords periodically. This control is important because:
- Limits exposure window: If a password is compromised, the attacker has a limited time to use it before the password expires
- Reduces hash value: Old password hashes that may have been extracted from breaches become useless after password changes
- Forces regular hygiene: Users must create new passwords regularly, reducing the chance of long-term password reuse across services
While NIST guidelines have shifted toward longer password ages (or no expiration) when combined with other controls like MFA, many compliance frameworks still require regular password changes. The 90-day recommendation balances security with usability.
Security Recommendationโ
Configure the maximum password age to 90 days or less (or 0 for never expire if using modern authentication with MFA). For environments without comprehensive MFA deployment, regular password changes remain important.
To configure this setting:
- Open Group Policy Management
- Navigate to the Default Domain Policy
- Edit: Computer Configuration > Policies > Windows Settings > Security Settings > Account Policies > Password Policy
- Set Maximum password age to 90 days or less
How the Test Worksโ
This test retrieves the default domain password policy using Get-ADDefaultDomainPasswordPolicy and extracts the MaxPasswordAge value. The test reports:
- Current maximum password age in days
- Recommended maximum (90 days)
- Whether the configuration meets security best practices
Related Testsโ
Test-MtAdPasswordHistoryCount- Checks password history enforcementTest-MtAdPasswordMinLength- Checks minimum password lengthTest-MtAdPasswordComplexityRequired- Checks if password complexity is enforced
Test Metadataโ
| Field | Value |
|---|---|
| Test ID | AD-PWDPOL-02 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.PasswordPolicy |
| PowerShell test | Test-MtAdPasswordMaxAge |
| Tags | AD, AD-PWDPOL-02, AD.PasswordPolicy |
Sourceโ
- Pester test:
tests/ad/passwordpolicy/Test-MtAdPasswordMaxAge.Tests.ps1 - PowerShell source:
powershell/public/ad/passwordpolicy/Test-MtAdPasswordMaxAge.ps1

