If we sync our production eDir to our Vault eDir, should the NMAS/UP
password policies be the same in both trees?

I'm guessing "no"?

From what I can tell, the only restriction on the vault tree is that
password expires every 120 days.

In the production tree, that same setting is there, in addition to a
bunch of other stuff (like must have 6 characters, etc.)

So I'm assuming this is okay? Based upon the logic that you may be
syncing things into the vault from other sources?

But I'm not sure if I should change that setting when we change our
production tree setting to every 90 days?

