Why does W2k allow blank passwords even with GPO configured?

From: sd_wireless@yahoo.com
Date: 09/25/02


Date: 25 Sep 2002 14:35:56 -0000
From: <sd_wireless@yahoo.com>
To: focus-ms@securityfocus.com


('binary' encoding is not supported, stored as-is)

We have a Domain GPO set that requires at least 8 characters in a
password, keeps a password history of 24 passwords to prevent password re-
use, and requires at least one day between password changes to prevent
someone from cycling through passwords and coming back around to the one
they were using. However, on accounts that existed before the GPO was
applied these restrictions are only partially taking affect.

For example, on any of these pre-GPO accounts, I can set a blank
password). Even though I can set a blank password I cannot set a password
with 1-7 characters. The password must either be blank or at least 8
characters. This occurs both from the Active Directory Users and Computer
MMC, and if a user does a CTRL-ALT-DEL and selects "Change Password".

For users that are created after the GPO exists, I cannot assign a blank
password. Obviously the GPO is applying or any password less than 8
characters would work. Still, since I have set a minimum at 8, why does it
let me set a blank password?



Relevant Pages

  • Password Policy
    ... I have the same problem here, GPO is configured for 5 ... characters, but the client machine ask for 6 ... >I'm helping a small business set up their server. ... >gpupdate /force, rebooted, but it will NOT work. ...
    (microsoft.public.windows.server.active_directory)
  • Re: GP0 - Pasword length doesnt ake
    ... they can do it with any number of characters?? ... Password policy, for domain accounts, can only be set in a GPO linked to ... If you set password policy in a GPO linked to an ... you are affecting local accounts on any computers in that OU. ...
    (microsoft.public.win2000.security)
  • Re: Query help?
    ... Codes ... GPO ... > One text: 10 characters ... Prev by Date: ...
    (microsoft.public.access.queries)
  • Re: change of Account policy in Domain security policy
    ... it will only apply to password changes. ... Joe Richards Microsoft MVP Windows Server Directory Services ... hsiwai wrote: ... If I change it to 8 characters, what will be the impact to the current users whose password is less than 8 characters? ...
    (microsoft.public.windows.server.active_directory)