RE: Group Policy: multiple password policies in the same domain?

From: Laura A. Robinson (laurarobinson_at_earthlink.net)
Date: 08/31/05

  • Next message: Laura A. Robinson: "RE: Group Policy: multiple password policies in the same domain?"
    To: "'Derick Anderson'" <danderson@vikus.com>, <focus-ms@securityfocus.com>
    Date: Wed, 31 Aug 2005 15:19:49 -0400
    
    

     Inline replies to a couple of different people.

    > > You can only set password policies affecting domain
    > accounts using the
    > > "default domain policy" GPO - ie. the GPO at the top of the AD tree
    > > for a particular domain.

    Actually, that's not the case. You can only affect domain accounts at the
    domain level, but you do NOT have to use the "Default Domain Policy" GPO.
    You can create your own and it works. If you have multiple domain-level
    policies that specify password settings, the last applied policy at the
    domain level will "win". My other post answering the original question got
    bounced, but I clarified some of this in it.

    > Does anyone know why the password policy is a computer and
    > not a user-based setting?

    Why would it be a computer setting? That would make no sense for all of the
    users in the domain who are people rather than computers. Again, you can
    only have a single password policy that affects accounts stored in AD for a
    given domain. Because both users and computers are stored in AD, the
    password policy applies to *any* account stored in AD.

    Laura

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------


  • Next message: Laura A. Robinson: "RE: Group Policy: multiple password policies in the same domain?"

    Relevant Pages

    • Re: Where to set the domain password policy up?
      ... Account Policies applied to Domain Controllers apply to all accounts stored on domain controllers - that is, to all domain accounts in that domain! ... I'd say apply at the domain level still - to have consistent policy for domain accounts in the domain as well as for local accounts on all computers in that domain. ... > Is it better to set a domain password policy up at the domain node level ...
      (microsoft.public.windows.server.active_directory)
    • Re: SOX compliant .. different password policy need for privil
      ... I am curious to know if once a forest and a root domain is created, ... have the password policy for the new ... match the existing domain, move all user accounts to the new domain, ... and keep the privileged accounts in the existing domain (after all ...
      (microsoft.public.win2000.active_directory)
    • Re: SOX compliant .. different password policy need for privil
      ... have the password policy for the new domain ... the password policy on the forest root domain to meet the SOX ... and force all administrative accounts to reset their passwords under the ... policy for all privilege accounts however our Win2003 forest consist ...
      (microsoft.public.win2000.active_directory)
    • Re: Password policy at the OU level
      ... password policy is enforced at the domain controllers. ... How do I handle service accounts? ... >>within a GPO linked to the domain level only. ...
      (microsoft.public.windows.group_policy)
    • Re: Password policy in domain 2003
      ... there is only one account and password policy for domain accounts. ... If one sets these at a different level (not at domain level) such as ... have impact on machine local accounts defined on the computers ...
      (microsoft.public.security)