There is nothing under NIS that will enable the features you want; also NIS (unlike NIS+) is absolutely imcompatible with a Trusted system.
NIS+ and trusted is a viable solution. As long as you are not one of those guys that have routines to edit passwd field directly via scripts, the conversion to trusted should be quite painless. The conversion to NIS+ requires a bit steeper learning curve and unfortunately in some ways your knowledge
of NIS may hurt you more than it helps --- it's that different. Conceptually they are similar but that is where the similarity ends.
The downside to NIS+ is that it is probably not a truly long-term solution. If I were you, I would take a hard look at LDAP.
If it ain't broke, I can fix that.