RE: Group Policy: multiple password policies in the same domain?

From: Derick Anderson (danderson_at_vikus.com)
Date: 08/31/05

  • Next message: Delgado, Jacob M.: "RE: Group Policy: multiple password policies in the same domain?"
    Date: Wed, 31 Aug 2005 10:25:01 -0400
    To: "Depp, Dennis M." <deppdm@ornl.gov>, <focus-ms@securityfocus.com>
    
    

    As I feared.

    Thanks,

    Derick

    > -----Original Message-----
    > From: Depp, Dennis M. [mailto:deppdm@ornl.gov]
    > Sent: Wednesday, August 31, 2005 10:18 AM
    > To: Derick Anderson; focus-ms@securityfocus.com
    > Subject: RE: Group Policy: multiple password policies in the
    > same domain?
    >
    > There can be only one password policy for the domain.
    >
    > Dennis
    >
    > -----Original Message-----
    > From: Derick Anderson [mailto:danderson@vikus.com]
    > Sent: Wednesday, August 31, 2005 7:32 AM
    > To: focus-ms@securityfocus.com
    > Subject: Group Policy: multiple password policies in the same domain?
    >
    > I'm trying to lock down some domain "service" accounts
    > (backup, Exchange, SQL Server, Scheduled Tasks, etc.) where I
    > work. We're an application service provider (web-based) and
    > we have only one domain at the moment (sigh), shared by our
    > production servers (big sigh) on the same physical network
    > (very big sigh). Our web application must run as a domain
    > account (throws up hands in exasperation).
    >
    > Splitting the domain into production and non-production is in
    > the works but will realistically be at least a couple months
    > away. In the mean time I'm trying to enforce stronger
    > passwords for service accounts like those I mentioned above
    > but I'm having problems using Group Policy to specify that
    > service accounts have a certain password policy while regular
    > users have another. I believe the problem is that password
    > policies are computer based instead of user based, so I can't
    > specify that specific users have one set of password policies
    > while others have a different one.
    >
    > Would applying the policy to a specific set of computers
    > affect only the local accounts on those computers, or the
    > entire domain? My theory is that only the password policy on
    > the domain controllers would affect domain passwords, but I'd
    > love to hear differently.
    >
    > Any help would be appreciated.
    >
    > Thanks,
    >
    > Derick Anderson
    >
    > --------------------------------------------------------------
    > ----------
    > ---
    > --------------------------------------------------------------
    > ----------
    > ---
    >
    >

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------


  • Next message: Delgado, Jacob M.: "RE: Group Policy: multiple password policies in the same domain?"

    Relevant Pages

    • Re: Password policy at the OU level
      ... Checkpoint issues with PPTP go back to the origin, ... >I would suggest that either you get their outbound VPN ... >password policy is enforced at the domain controllers. ... How do I handle service accounts? ...
      (microsoft.public.windows.group_policy)
    • Re: Enforce "Password Never Expires" Setting?
      ... This feature allows you to configure a different password policy to a user or group. ... So in your case, you would have to create a shadow group, add all your service accounts to the shadow group, create a PSO that sets the maximum password age to 0, and apply the PSO to the shadow group that you created. ... logoff script would seem moot since the service account never actually logs ...
      (microsoft.public.windows.group_policy)
    • Domain Password Policy
      ... The only password policy we currently enforce in our 1 domain is a minimum ... Minimum password length - 8 characters ... We currently have numerous damain service accounts that do NOT meet the ...
      (microsoft.public.win2000.security)
    • Re: Re: Changing the domain password policy
      ... You deal with the Service Account passwords by making them comply with your password policy. ... you can create as many different password policies as you like - the Domain Password Policy will be the one actually applied to all users. ... I suppose that if you wanted to be extra safe, you could make a policy just for the service accounts, and have a different set of password requirements for these accounts, and have the default domain policy have the stronger password complexity settings. ...
      (Security-Basics)
    • Re: Please Help: Someone is hacking my server!
      ... That's probably why Windows Integrated is the recommended security model. ... Why duplicate all of Windows' password policy functionality in SQL Server ... Are you exposing Terminal Services to the Internet as well, ...
      (microsoft.public.sqlserver.security)