Password policy evaluation
To evaluate an effective password policy for the user, all password policies that are associated with a user are considered with the individual password policy.
The group password policy is considered and finally the global
password policy is considered. If an attribute is not defined in the
individual password policy entry, it is searched in the composite
group password policy entry. If it is not found in the composite group
policy entry, the attribute in the global password policy entry is
used. If the attribute is not defined in the global password policy
entry, then the default value is assumed.
Note: The effective password
policy extended operation (effectpwdpolicy) is
used to display the effective password policy of a specified user.
Information about the password policy entries that are used to calculate
the effective password policy is also displayed by using this extended
operation. For more information about this extended operation, see
the Command Reference section.