RE: Account Lockout Policy

From: Alexander Suhovey (asuhovey_at_mtu-net.ru)
Date: 10/22/05

  • Next message: Mike MacNeill: "RE: Account Lockout Policy"
    To: 'Rasmus RŪnlev' <rr.it@cbs.dk>, <focus-ms@securityfocus.com>
    Date: Sun, 23 Oct 2005 00:05:04 +0400
    
    

    > -----Original Message-----
    > From: Rasmus RŪnlev [mailto:rr.it@cbs.dk]
    > Sent: Friday, October 21, 2005 1:37 AM
    > To: focus-ms@securityfocus.com
    > Subject: Re: Account Lockout Policy
    >
    > Hi,
    >
    [..]
    > It seems some of the responding
    > people are knee-jerk-reacting to "you can only put into
    > effect account policy from the domain level". This is correct
    > in so far that "Domain Policy" will be applied towards Domain
    > Controllers, sitting in the Domain Controllers OU.

    Not quite. Having DCs in GPO scope is not how it works for
    domain account policies. If you greate a GPO linked to Domain
    Controllers OU, DCs will ignore account policies configured
    in this GPO. Domain account policies must be configured
    only at the root level of domain.
    Here's a couple of quotes from [2]:
    "Password policies, Kerberos, and some security options are
    only merged from GPOs that are linked at the root level on
    the domain. This is done to keep those settings synchronized
    across all domain controllers in the domain."

    "For domain accounts, only one account policy is permitted per
    domain. This account policy must be specified in the Default
    Domain Policy GPO, or in a new GPO that is linked to the root
    of the domain and has precedence over the Default Domain
    Policy GPO. [...] A domain controller always gets the account
    policy from a GPO linked to the domain, by default from the
    Default Domain Policy GPO."

    1. "Where does your client's security policy actually come from?"
    http://searchwin2000.techtarget.com/tip/1,289483,sid1_gci1108125,00.html

    2. "How Security Settings Extension Works"
    http://www.microsoft.com/technet/prodtechnol/windowsserver2003/library/TechR
    ef/824b4758-9430-4633-8d8f-3dad0f2bf839.mspx

    --
    Al
    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------
    

  • Next message: Mike MacNeill: "RE: Account Lockout Policy"

    Relevant Pages

    • Re: Auditing Account Lockouts
      ... In the GPO for DC's, we have success/failure checked, turned on ... for Audit account logon events, ... it does not show up on the Domain controllers security logs. ... identify the machine where the lockout is occuring. ...
      (microsoft.public.security)
    • Re: Passowrd complexity LOCAL Account
      ... Place this computer account into an OU. ... Then, link a new GPO to the OU, ... configuring the GPO's Account Policy like you want the local SAM to behave. ... > local user accounts with passwords that do not follow the ...
      (microsoft.public.win2000.group_policy)
    • Re: starting over with GPO
      ... Your description does not take into account the concept of Group Policy ... you would only need to link the Domain GPO to the domain and Users ... See the following link for a description of Group Policy Inheritance: ...
      (microsoft.public.windows.group_policy)
    • Re: Domain Admin account and lockout Policy
      ... have different account policies for different domain user accounts, ... Topics, Group Policy Management, Concepts, Group Policy Object Editor ... Default Domain Policy Group Policy object (GPO) or in a new GPO that ...
      (microsoft.public.windows.group_policy)
    • Re: Domain Admin account and lockout Policy
      ... have different account policies for different domain user accounts, ... Topics, Group Policy Management, Concepts, Group Policy Object Editor ... Default Domain Policy Group Policy object (GPO) or in a new GPO that ...
      (microsoft.public.windows.group_policy)