It is not uncommon for Mac users to login with local user accounts, even in a directory environment. The question becomes, how do we enforce password policies on those local accounts? There are many schools of thought on this but here is how I did it recently with the combination of a configuration payload and a simple script.