I have been attempting to reset the Domain Security policy for account passwords. I have made the changes to the defauly domain policy in Group Policy at our win2k server. I have checked the local policy setting on the computer for the user whose password I want to reset. Although the effective settings on the workstation now reflect the changes from the server, I still cannot make the change. I have even used the "secedit /refreshpolcy machine-policy /enforce" command and checked the settings in mmc without success. This particular user's account expires on August 23 and he wants to keep his old password contrary to the original domain policy. What do I need to do to make this change effective? Would it be better to move the user into a separate organizational unit?