Domain – Difference between forcing a password change and an expired password


There seems to be a subtle difference between a domain account that has the checkbox "force password change" and an account that merely has an expired password (say after 90 days).

Is there a way to simulate / force an account to "expire" other than changing the policy and impacting all accounts? Are there differences based on the functional level of the domain?

Best Answer

You can set the user's pwdlastset attribute to a specific date/time therefore making it expired. You can do that using powershell, wsh, vbs, ... Note however that the format of the field is Integer8