Password policy in domain 2003

Password policy in domain 2003

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Password policy in domain 2003 04-28-2008
Posted by =?Utf-8?B?15zXmdeQ15XXqC7XpA== on April 28, 2008, 7:21 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi

As far as I know there can be only one password policy.
I configured the main GPO in the root for specific password policy, I have
an OU with blocked inheritance is checked, and I created a new gpo and linked
it to this OU, this gpo have a diffrent set of password policy, I run the
RSOP on the server under that OU, and I got the new set of password policy
that is linked to this OU.
So, Can I use a diffrent password policy in diffrent OU's ?
or, I missing somthing?

thanks

Lior


Posted by Dobromir Todorov on April 28, 2008, 8:26 am
If you were  Registered and logged in, you could reply and use other advanced thread options
You can - but for accounts that reside in the local SAM databases of
computers in that OU. You will certainly notice that it only applies to
computers, and not to users. For domain accounts, the domain level password
policy still applies.

--
---
HTH,
Dobromir

Learn more about Security and Identity Management:
Visit http://www.iamechanics.com

> Hi
>
> As far as I know there can be only one password policy.
> I configured the main GPO in the root for specific password policy, I have
> an OU with blocked inheritance is checked, and I created a new gpo and
> linked
> it to this OU, this gpo have a diffrent set of password policy, I run the
> RSOP on the server under that OU, and I got the new set of password policy
> that is linked to this OU.
> So, Can I use a diffrent password policy in diffrent OU's ?
> or, I missing somthing?
>
> thanks
>
> Lior
>



Posted by =?Utf-8?B?15zXmdeQ15XXqC7XpA== on April 28, 2008, 9:47 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi
I didn't anderstand your answer, can U pleas explain broadly, the password
policy
is on the computer section, when u wrote " For domain accounts, the domain
level password policy still applies", the computer object account are domain
accounts, so what did u mean?

Lior

"Dobromir Todorov" wrote:

> You can - but for accounts that reside in the local SAM databases of
> computers in that OU. You will certainly notice that it only applies to
> computers, and not to users. For domain accounts, the domain level password
> policy still applies.
>
> --
> ---
> HTH,
> Dobromir
>
> Learn more about Security and Identity Management:
> Visit http://www.iamechanics.com
>
> > Hi
> >
> > As far as I know there can be only one password policy.
> > I configured the main GPO in the root for specific password policy, I have
> > an OU with blocked inheritance is checked, and I created a new gpo and
> > linked
> > it to this OU, this gpo have a diffrent set of password policy, I run the
> > RSOP on the server under that OU, and I got the new set of password policy
> > that is linked to this OU.
> > So, Can I use a diffrent password policy in diffrent OU's ?
> > or, I missing somthing?
> >
> > thanks
> >
> > Lior
> >
>
>
>

Posted by Roger Abell [MVP] on April 28, 2008, 11:10 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Dobromir stated correctly that prior to Windows 2008 domains
there is only one account and password policy for domain accounts.
If one sets these at a different level (not at domain level) such as
your case on an OU, then the account and password policies will
have impact on machine local accounts defined on the computers
in that OU, which is why you were seeing what you report in the
GP results for machines in that OU.

Roger

> Hi
> I didn't anderstand your answer, can U pleas explain broadly, the password
> policy
> is on the computer section, when u wrote " For domain accounts, the domain
> level password policy still applies", the computer object account are
> domain
> accounts, so what did u mean?
>
> Lior
>
> "Dobromir Todorov" wrote:
>
>> You can - but for accounts that reside in the local SAM databases of
>> computers in that OU. You will certainly notice that it only applies to
>> computers, and not to users. For domain accounts, the domain level
>> password
>> policy still applies.
>>
>> --
>> ---
>> HTH,
>> Dobromir
>>
>> Learn more about Security and Identity Management:
>> Visit http://www.iamechanics.com
>>
>> > Hi
>> >
>> > As far as I know there can be only one password policy.
>> > I configured the main GPO in the root for specific password policy, I
>> > have
>> > an OU with blocked inheritance is checked, and I created a new gpo and
>> > linked
>> > it to this OU, this gpo have a diffrent set of password policy, I run
>> > the
>> > RSOP on the server under that OU, and I got the new set of password
>> > policy
>> > that is linked to this OU.
>> > So, Can I use a diffrent password policy in diffrent OU's ?
>> > or, I missing somthing?
>> >
>> > thanks
>> >
>> > Lior
>> >
>>
>>
>>



Posted by on April 30, 2008, 2:42 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Have a look at http://www.specopssoft.com/products/specopspasswordpolicy
at the Specops Password Policy product. It will cover your needs.

Regards

Joachim

Similar ThreadsPosted
Unable to reset 2003 domain password policy. October 17, 2006, 8:21 am
Password policy change on domain September 28, 2006, 9:25 am
Windows Server 2003 password policy September 1, 2005, 12:51 pm
Change 2003 Domain Password over Internet (No outlook, no vpn)... February 17, 2007, 12:47 pm
Domain Policy vs Local Policy September 29, 2005, 5:02 pm
Password Policy forces to change password - but too late... June 27, 2007, 6:32 am
default domain policy + EFS June 7, 2007, 10:50 am
Default domain Policy error August 29, 2006, 8:49 pm
Server 2003 Group policy August 10, 2006, 1:00 am
Domain Group Policy is not applying to workstation March 15, 2006, 2:11 pm

The site map in XML format XML site map

Contact Us | Privacy Policy