Step 4: View a Resultant PSO for a User or a Global Security Group
Updated: August 24, 2007
Applies To: Windows Server 2008, Windows Server 2008 R2
You can view the resultant Password Settings object (PSO) for a user object:
-
Viewing the resultant PSO for users using the Active Directory module for Windows PowerShell
-
Viewing the resultant PSO for users using the Windows interface
-
Viewing the resultant PSO for users from the command line using dsget
To view the resultant PSO (fine-grained password policy) for users using the Active Directory module for Windows PowerShell see, Get Resultant Password Policy of a User.
-
Open Active Directory Users and Computers. To open Active Directory Users and Computers, click Start, point to Administrative Tools, and then click Active Directory Users and Computers.
-
On the View menu, ensure that Advanced Features is checked.
-
In the console tree, click Users.
Where?
-
Active Directory Users and Computers\domain node\Users
-
Active Directory Users and Computers\domain node\Users
-
In the details pane, right-click the user account for which you want to view the resultant PSO, and then click Properties.
-
Click the Attribute Editor tab, and then click Filter.
-
Ensure that the Show attributes/Optional check box is selected.
-
Ensure that the Show read-only attributes/Constructed check box is selected.
-
Locate the value of the msDS-ResultantPSO attribute in the Attributes list.
Note If the value of the msDS-ResultantPSO attribute is Null, the Default Domain Policy is applied to the selected user account.
-
Open a command prompt. To open a command prompt, click Start, click Run, type cmd, and then click OK.
-
Type the following command, and then press ENTER:
dsget user <User-DN> -effectivepso
Example: dsget user "CN=u1,CN=Users,DC=corp,DC=contoso,DC=com" -effectivepso
Note If the PSO name is not returned by the dsget command, the Default Domain Policy is applied to the specified user account.
| Parameter | Description |
|---|---|
|
dsget user |
Displays various properties of a user in the directory. |
|
<User-DN> |
Specifies full distinguished name of the user object for which you want to view the resultant PSO. |
|
-effectivepso |
Specifies the resultant PSO. |
