you can only have 1 password policy in a domain, so you could set the
maximum password age to 0 but it would affect all your user accounts in your
If you had windows server 2008, you could utilize the fine grained password
feature. This feature allows you to configure a different password policy
(called a PSO -password setting object) to a user or group. You cannot
apply it to an OU, however.
So in your case, you would have to create a shadow group (a group that
includes all the members of an OU), add all your service accounts to the
shadow group, create a PSO that sets the maximum password age to 0, and
apply the PSO to the shadow group that you created.