So, I assume that my position is not that unique. Most of our users are using Macs joined to AD and login in with AD accounts. However we have some systems that are either not joined to AD or have a local account for development or some other reason.
Our CyberSec group wants us to enforce a password policy, but I can't figure out how to limit enforcement to only local accounts. Since our PW Policy in AD is set to require 3 of 4 criteria (A-Z, a-z, 0-9, special) and Apple's Config Profile or pwpolicy tool only allow you to set required or not (and only alphanumeric and special, no option for upper and lower case), I have had situations where a user was not able to login because of the conflict in policy.
Ideally I'd like to enforce a strict password but only for Local users with an ID over 500. Anyone been able to do this?
