Right now, if you turn on password expiration for built in accounts, users just get locked out the day it expires, no warning at all. This is tough for field staff who are not IT people and have no idea why they suddenly cannot log in. It is even worse for service accounts running scheduled scripts, since those just start failing with zero notice to the admin.