Password policy evaluation

To evaluate an effective password policy for the user, all password policies that are associated with a user are considered with the individual password policy.

The group password policy is considered and finally the global password policy is considered. If an attribute is not defined in the individual password policy entry, it is searched in the composite group password policy entry. If it is not found in the composite group policy entry, the attribute in the global password policy entry is used. If the attribute is not defined in the global password policy entry, then the default value is assumed.
Note: The effective password policy extended operation (effectpwdpolicy) is used to display the effective password policy of a specified user. Information about the password policy entries that are used to calculate the effective password policy is also displayed by using this extended operation. For more information about this extended operation, see the Command Reference section.