|
Posted by =?Utf-8?B?aWtiZWE=?= on June 13, 2005, 12:11 am
If you were Registered and logged in, you could reply and use other advanced thread options
For further information
In All DCs, the
"Domain Controoler Security Policy", "Domain Security Policy"
local setting = not defined
effective setting = not defined
In PDC, "local policy" --> account lockout threshold
local setting = 0 invalid logon attempts
effective setting = not defined (WHY ??)
In two BDC, local policy --> account lockout threshold
local setting = 0 invalid logon attempts
effective setting = 0 invalid logon attempts
Thanks
"ikbea" wrote:
>
> Three domain controller: one primary and two backup
> Member servers (joined same DC) : MServer1, MServer2
> All are windows 2000 SP3 servers
>
> I want to set account policy in MServer1 and MServer2:
> Account Lockout duration: Not defined (original) --> 30minutes (new)
> Account Lockout threshold: 0 (original) --> 5 (new) invalid logon attempts
> Reset account lockout counter after: Not defined (original) --> 30minutes
> (new)
>
> In MServer, all settings were changed as I expected.
> However, for MServer2, in "local policy settings --> account lockout
> threshold", the local setting = 5, the effective setting = 0.
>
> In DC, the
> "Domain Controoler Security Policy", "Domain Security Policy" and "Local
> Security Policy", the effective setting = not defined
>
> I tried to change MServer2 account lockout threshold to 5 in "Local
> Sercurity Policy", "MMC-->Group policy" and "MMC-->Security Configuration and
> Analysis", but the effective setting is still = 0
>
> How to set account lockout threshold to 5 in MServer2?
|