RE: security policy 'not specified' option

From: Tony King (agkcomputers_at_btinternet.com)
Date: 10/21/05

  • Next message: Thor (Hammer of God): "Re: security policy 'not specified' option"
    To: <focus-ms@securityfocus.com>
    Date: Thu, 20 Oct 2005 23:45:56 +0100
    
    

    If you have 'No Over-ride' set at the domain level for the OU in AD then you
    can stop local policy changes

    -----Original Message-----
    From: matthew patton [mailto:pattonme@yahoo.com]
    Sent: 20 October 2005 23:31
    To: Tony King
    Subject: RE: security policy 'not specified' option

    > Once you have set a policy from Not Defined you can only select
    > enable or
    > disable, unless you reload the policy files from a clean build

    and therein lies the rub. MS conveniently doesn't let me do that any
    more. does a domain policy categorially override any local settings?
    Somehow I really doubt that would be the case.

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------


  • Next message: Thor (Hammer of God): "Re: security policy 'not specified' option"

    Relevant Pages

    • Re: Security hierarchy
      ... can be configured only at domain level. ... would only apply to local machine accounts if domain policy is overridden.. ... I have found that sometimes certain settings do not "show up" in a timely ... > Currently Domain and DC Security policy have all display password ...
      (microsoft.public.win2000.security)
    • Re: Domain
      ... Domain Controller Security Policy has all user rights assignments ... Configuring ipsec policy at the domain level ...
      (microsoft.public.win2000.group_policy)
    • Re: Security hierarchy
      ... policy level also. ... >>can be configured only at domain level. ... Try running security configuration and ... >>try not to change domain and domain controller policy, ...
      (microsoft.public.win2000.security)
    • Re: Login Scripts
      ... Default Domain Policy) that contains the "baseline" settings that users ... at the OU level will override settings declared at the domain level, and GPO ... > domain if no MSI package is found. ...
      (microsoft.public.windows.server.active_directory)
    • Re: Account Lockout Threshold change - Not taking effect
      ... The other policy is linked at the domain level. ... I even changed the settings to 5 attempt. ... Have you tried unlinking the additional GPO you've created at the Domain ...
      (microsoft.public.windows.server.active_directory)