We require 15+ mixed character passwords for service accounts.

Domain Admin logons & above require a SecureID-type dongle.
Oh, and as expected, that dongle needs a PIN to work.

Could be better, but it's a start.

Rootoo