What is the Minimum Password Length for User1?
Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains a user named User1. User1 is a member of a group named Group1 and is in an organizational unit (OU) named OU1. The domain has minimum password lengths configured as shown in the following table. What is the minimum password length that User1 should use when changing to a new password? - 
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests FGPP inheritance and precedence hierarchy, with the common trap being confusion over OU-linked GPOs versus direct PSO assignments.
This question evaluates understanding of Active Directory Fine-Grained Password Policy (FGPP) precedence rules. Community consensus confirms that a directly assigned Password Settings Object (PSO) overrides all other policy sources, resulting in a minimum length of 7 characters.
Option E (14) is frequently selected due to overestimating default security baselines, but candidates incorrectly assume OU-level settings or domain defaults override direct PSO assignments.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Fine-Grained Password Policies enable administrators to define multiple distinct password requirements within a single domain. Microsoft enforces a strict precedence hierarchy where a PSO directly applied to a user object always takes priority over group-assigned PSOs and the default domain policy. Because User1 has a PSO explicitly linked to their account with a minimum length of 7, this configuration immediately overrides all other potential settings.Why the Other Options Are Wrong
Options B, C, D, and E reflect higher character counts that might appear in default domain policies or stricter organizational settings. Standard Group Policies linked to Organizational Units cannot enforce password length requirements, rendering those values ineffective in this scenario. Furthermore, group-assigned PSOs would only be evaluated if no direct assignment existed, making longer lengths like 14 completely incorrect for this specific user.Community Comment Notes
Multiple verified candidates confirm option A after conducting hands-on lab validations, reinforcing the direct PSO precedence rule. Comment [1] accurately maps out the exact precedence order required to solve this problem, while comment [3] correctly clarifies that OU-linked GPOs never apply to password policies. These practical insights align seamlessly with official Microsoft certification objectives for hybrid server administration.Official Reference
Exam Strategy
Memorize the exact precedence order for FGPP: Direct Assignment > Group Membership > Default Domain Policy. Always scan for direct object assignments first before evaluating group or domain-level settings during the exam.