What is the Minimum Password Length for User1?

Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains a user named User1. User1 is a member of a group named Group1 and is in an organizational unit (OU) named OU1. The domain has minimum password lengths configured as shown in the following table. What is the minimum password length that User1 should use when changing to a new password? - image

  1. 7 Source Reference Answer
  2. 8
  3. 10
  4. 12
  5. 14

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests FGPP inheritance and precedence hierarchy, with the common trap being confusion over OU-linked GPOs versus direct PSO assignments.

This question evaluates understanding of Active Directory Fine-Grained Password Policy (FGPP) precedence rules. Community consensus confirms that a directly assigned Password Settings Object (PSO) overrides all other policy sources, resulting in a minimum length of 7 characters.

Option E (14) is frequently selected due to overestimating default security baselines, but candidates incorrectly assume OU-level settings or domain defaults override direct PSO assignments.

Community Discussion (6 comments)

Jothar 👍 1
A is correct. I would like to point out that, if it's not a Password Settings Object, the ONLY gpo that can create a password length policy is default domain policy. A gpo linked to an ou with a password policy will never apply.
monisshk 👍 2
Correct answer: A Tested in LAB.
Krayzr 👍 1 Selected: A
Seems to be correct
bpaccount 👍 1 Selected: A
A is correct. Tested it.
IcE 👍 1 Selected: E
User1 is apart of Group1. In AD, the most specific policy applies
SIAMIANJI 👍 4 Selected: A
When determining the minimum password length that User1 should use when changing to a new password, the following precedence order should be considered: Password Settings object applied directly to the user (User1). Password Settings object applied to the user's group (Group1). Group Policy linked to the user's organizational unit (OU1). Default Domain Policy. Default Domain Controllers Policy. Based on the precedence order and the configuration provided: Password Settings object applied to User1: 7 Password Settings object applied to Group1: 14 Group Policy linked to OU1: 8 Default Domain Policy: 10 Default Domain Controllers Policy: 12 User1's minimum password length will be determined by the Password Settings object applied directly to the user (User1), which specifies a minimum password length of 7 characters. Therefore, User1 should use a minimum password length of 7 characters when changing to a new password.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Fine-Grained Password Policies enable administrators to define multiple distinct password requirements within a single domain. Microsoft enforces a strict precedence hierarchy where a PSO directly applied to a user object always takes priority over group-assigned PSOs and the default domain policy. Because User1 has a PSO explicitly linked to their account with a minimum length of 7, this configuration immediately overrides all other potential settings.

Why the Other Options Are Wrong

Options B, C, D, and E reflect higher character counts that might appear in default domain policies or stricter organizational settings. Standard Group Policies linked to Organizational Units cannot enforce password length requirements, rendering those values ineffective in this scenario. Furthermore, group-assigned PSOs would only be evaluated if no direct assignment existed, making longer lengths like 14 completely incorrect for this specific user.

Community Comment Notes

Multiple verified candidates confirm option A after conducting hands-on lab validations, reinforcing the direct PSO precedence rule. Comment [1] accurately maps out the exact precedence order required to solve this problem, while comment [3] correctly clarifies that OU-linked GPOs never apply to password policies. These practical insights align seamlessly with official Microsoft certification objectives for hybrid server administration.

Official Reference

Exam Strategy

Memorize the exact precedence order for FGPP: Direct Assignment > Group Membership > Default Domain Policy. Always scan for direct object assignments first before evaluating group or domain-level settings during the exam.

Related Analysis

← Back to AZ-800 Study Guide