Re: Backing out Complex passwords enabled in Domain Group policy.

From: Steven L Umbach (sumbach_at_nospam-ameritech.net)
Date: 03/05/04


Date: Fri, 05 Mar 2004 14:32:22 GMT

Hi Herb.

You bring up some excellent points. I gave the quick usual answer of first
thing to try. Of course if there is more than one GPO for the domain, then
any settings at the GPO highest in the list will take precedence and if
there is more than one they should dusable complexity on the top domain GPO
also which may not be obvious if someone is just trying Domain Security
Policy in administative tools.

Supposedly [and I might be wrong] it should not matter if it is configured
in Domain Controller Security Policy and my experience shows that, though it
would not hurt to disable it there also. However if a change is made to the
domain level and "block inheritance" is configured on the domain controller
container then password policy changes will not be implemented.

I also found that often the "effective" settings shown in Local Security
Policy even after a reboot can be incorrect and one way to tell what the
real effective settings are to run Security Configuration and Analysis
ool. --- Steve

http://support.microsoft.com/default.aspx?scid=kb;en-us;269236

"Herb Martin" <news@LearnQuick.com> wrote in message
news:e8isoMnAEHA.2768@tk2msftngp13.phx.gbl...
> "Steven L Umbach" <n9rou@nospam-comcast.net> wrote in message
> news:v6P1c.179508$uV3.762298@attbi_s51...
> > Change complexity to disabled in the domain policy. Ten run secedit
> /refreshpolicy
> > machine_policy /enforce. Wait a couple of minutes and try again. ---
> Steve
> >
>
> I agree with you Steven but I have another thought about what
> MIGHT have been done, correct me if you disagree, this is only
> a supposition....
>
> IF he changed the Domain Controller Policy (and forgot that) or
> added another policy besides default (this is obviously true but I
> am trying to be complete) then he might be trying to "fix" it in only
> one of several places it is set.
>
> --
> Herb Martin
> >
> > "Tony Gec" <tony.gec@parliament.qld.gov.au> wrote in message
> > news:C26CC5B2-686B-4EC8-9C01-C9EE28D74BCF@microsoft.com...
> > > Hi,
> > >
> > > I'm currently testing the use of enabling complex passwords. It all
> works fine,
> > however I've been requested to test backing it out.
> > >
> > > Here's my problem.
> > >
> > > Although I have changed the Domain Group policy for complex passwords
> back to the
> > original setting (not defined). Every time I try to add a new user or
> have an
> > existing user change their password, the system insists on using complex
> passwords
> > instead of basic passwords. RSoP indicates that complex passwords have
> been turned
> > off.
> > >
> > > Is there anything else I need to do on the Domain Controller?
> > >
> > > Cheers,
> > >
> > > Tony Gec.
> >
> >
>
>



Relevant Pages

  • Re: GPO Update Problem (SYSVOL access via UNC)
    ... Server Security and Auditing Policy ... This list only includes links in the domain of the GPO. ... The settings in this GPO can only apply to the following groups, users, ...
    (microsoft.public.win2000.group_policy)
  • Re: GPO Update Problem (SYSVOL access via UNC)
    ... > Server Security and Auditing Policy ... > This list only includes links in the domain of the GPO. ... > The settings in this GPO can only apply to the following groups, users, ...
    (microsoft.public.win2000.group_policy)
  • Re: Group Policy is now inhibiting the Administrator account
    ... under Group Policy Objects - those are the individual GPOs. ... You can apply any given GPO to one or more OUs, ... I use all of the default security in SBS, ... log on to the server with your own account. ...
    (microsoft.public.windows.server.sbs)
  • Re: GPO not picking up computer settings
    ... to the domain container with the password/account settings you want. ... for password/account settings and from what GPO. ... buying any of the highly rated AD or Group Policy books you see at Amazon or ... I have changed all the passwords back to what they were so users are now ...
    (microsoft.public.windows.server.security)
  • Re: TimeOut Script for OWA
    ... Security MVP Dana Epp has developed a two factor authentication that will defeat any amount of password guessing or scripted attempts. ... >> Since Merv said his knowledge of group policy is limited, ... You should not 'enforce'>> a ... >>> on a GPO overrides any 'conflicting' GPO settings that you might ...
    (microsoft.public.windows.server.sbs)