Code : MO-AD-003 | Version : 1.0 | Date : 31 mars 2026 | Auteur : C. Legrand
Ce mode operatoire decrit la creation et la gestion de politiques de mots de passe differenciees (Fine-Grained Password Policies, FGPP) dans le domaine Active Directory bts.sio. Les FGPP appliquent des exigences proportionnelles au niveau de privilege, conformement au modele ANSSI d'administration en tiers (2023).
| FGPP | Groupes | Min. chars | Lockout | Expiration | Precedence |
|---|---|---|---|---|---|
| FGPP-Admins | Admins du domaine (4) | 16 | 5 / 60 min | 90 j | 10 |
| FGPP-Staff | GGPROFS (9 profs) | 12 | 10 / 30 min | 180 j | 20 |
| FGPP-Etudiants | GGPromoSio1 (34) + GGPromoSio2 (23) | 10 | 10 / 15 min | 365 j | 30 |
(Get-ADDomain).DomainMode
# Resultat attendu : Windows2016Domain ou superieur

New-ADFineGrainedPasswordPolicy -Name "FGPP-Admins" `
-Precedence 10 -MinPasswordLength 16 `
-PasswordHistoryCount 24 -ComplexityEnabled $true `
-MaxPasswordAge "90.00:00:00" -MinPasswordAge "1.00:00:00" `
-LockoutThreshold 5 -LockoutDuration "01:00:00" `
-LockoutObservationWindow "01:00:00" `
-ReversibleEncryptionEnabled $false
Add-ADFineGrainedPasswordPolicySubject -Identity "FGPP-Admins" `
-Subjects "Admins du domaine"

Get-ADFineGrainedPasswordPolicy -Filter * |
Format-List Name, Precedence, MinPasswordLength,
LockoutThreshold, MaxPasswordAge, AppliesTo

Get-ADUserResultantPasswordPolicy -Identity "clegrand"
# Doit retourner FGPP-Admins (MinLen=16)

# Modifier un parametre
Set-ADFineGrainedPasswordPolicy -Identity "FGPP-Admins" -LockoutThreshold 3
# Retirer un groupe
Remove-ADFineGrainedPasswordPolicySubject -Identity "FGPP-Admins" `
-Subjects "Admins du domaine" -Confirm:$false
# Supprimer une FGPP
Remove-ADFineGrainedPasswordPolicy -Identity "FGPP-Admins" -Confirm:$false