Re: Security hierarchy

From: Peter K. (pmkdatabase@yahoo.ca)
Date: 04/13/03


From: Peter K. <pmkdatabase@yahoo.ca>
Date: Sun, 13 Apr 2003 11:52:10 +0700


Thank you - I hope you have time to have a look at my responses
inline.

On Sat, 12 Apr 2003 15:03:09 GMT, "Steven L Umbach"
<sumbach@ameritech.net> wrote:

> I assume you are trying to add a domain user. Account policy for domain

Yes

>can be configured only at domain level. If it is assigned at other levels it
>would only apply to local machine accounts if domain policy is overridden..

Understood, but at domain level (and DC) it is not defined.

>I have found that sometimes certain settings do not "show up" in a timely
>manner as you would think. Try running security configuration and analysis

It has been > 12 hours or so since my post, and I have rebooted also.

>snap in to see what it reports.

Not Configured - PasswordComplexity

>Another thing to try would be to change
>setting to disabled at domain level. These policies do not propagate

Tried that.

>immediately and need to be updated on dc first via a secedit refresh or
>reboot before doing same to domain member computer. It is also advisable to

ran secedit and rebooted also.

>try not to change domain and domain controller policy, but to add new
>policies for desired changes - that way it is easy to undo changes and go
>back to default by deleting custom policy.

Good advice for next time!

This is the big question: Are you saying that from the info I have
provided, that password complexity should not be enforced although it
is and therefore the system is somehow hosed? 'Cause if so, I will
stop wasting time on it but it is scary if it could get hosed so
easily.

>Changes at local security policy
>can be restored to default, but it is best to document changes and do just a
>few at a time. -- Steve
>
>"Peter K." <pmkdatabase@yahoo.ca> wrote in message
>news:s4lf9v0mcbl10ab7fq3m0au9du2l7mujt8@4ax.com...
>> Hi,
>>
>> Maybe I have been working on this too long (studying for the 70-215
>> exam) - but I just cannot figure out what is going on. Help would be
>> appreciated. I should mention I have made a number of changes to the
>> security settings at various levels.
>>
>> Currently Domain and DC Security policy have all display password
>> policies 'not defined'. The default GPO for the domain in Users and
>> Computers MMC also shows them as all not defined. Local setting show
>> password complexity requirement as disabled in Local Settings, and
>> Effectively as 'not defined'.
>>
>> I reboot the DC (the only one in the test domain).
>>
>> Yet password complexity is clearly in effect - I cannot add a user -
>> regardless of the group selected - unless the password meets
>> complexity requirements like so.123Ss11D. What am I missing??
>>
>> Thanks,
>>
>> Peter
>>
>>
>> Peter
>

Peter



Relevant Pages

  • Re: What Happened? Passwords all expired...
    ... really explain how the new account policy settingmade it to the DCs. ... I would strongly suggest enabling Success/Failure for Account Management ... >>>post that says "I check my GPO's and password complexity ... >>>>account logon events success and fail ...
    (microsoft.public.win2000.active_directory)
  • Re: GPO - password policy - Urgent
    ... Set password complexity to "disabled" - NOT undefined in Domain ... You can also use the mmc snapin for Resultant Set of Policy [again ... assuming Windows 2003] in logging mode on the domain controller to see what ... problems being that domain controllers are not pointing only to themselves ...
    (microsoft.public.windows.server.security)
  • Re: CTRL ALT DEL function disabled locally
    ... Keep in mind that if you setup the OU with a Group Policy, that security ... the problem computer for a remote command prompt if that would help. ... Upon reboot I was immediately locked out without the ...
    (microsoft.public.win2000.security)
  • Re: FC3 and selinux
    ... >will be running under the correct policy, but will let you login if there is a problem such as ... >incorrect file context labeling. ... >Tell the init scripts to relabel the system on reboot with the command touch /.autorelabel. ...
    (Fedora)
  • Re: Using gpupdate /force doesnt update settings, only reboot does
    ... it will take a reboot to apply. ... I've tried 2 things to verify if the policy apply: ... Darren Mar-Elia wrote: ... What are the settings that you're trying to apply? ...
    (microsoft.public.windows.group_policy)