I am setting up user accounts for MAB (Mac Authentication Bypass) devices on my network. In GPO I have made an OU for the device accounts to be created with block inheritance so that the password policy is not applied to the device accounts. The password policy does apply to the Domain Controller. When I go to make the account for the device the username/password must be the mac address of the device. Problem is even with the block inheritance set on the OU when I got to make the user account in that OU it still enforces the password policy. Without turning the policy with the password policy off, is there a way to make the user account for the MAB deivce?
The password policy which is applied to Domain Controllers affects all users in the domain, regardless of where you place them in the Active Directory tree. OU inheritance is completely unrelated.
You can use fine grained password policies to apply different password policies to specific users (or group of users).