We have our macs bound to AD (transitioning to NoMAD in the works).
About 5 months ago we added a tiered password expiration based on
password length using following article:
http://techgenix.com/Configuring-Granular-Password-Settings-Windows-Server-...