Re: Domain vs Local Security Policy

From: Paul Adare - MVP - Microsoft Virtual PC (padare_at_newsguy.com)
Date: 03/05/04


Date: Fri, 5 Mar 2004 14:48:37 -0500

In article <803201c402e6$67e28a90$a101280a@phx.gbl>, in the
microsoft.public.win2000.security news group, Rich
<anonymous@discussions.microsoft.com> says...

> This is not true. You can create a separate OU with it's
> own password policy and block the policy inheritance from
> the parent.
>

No, you're wrong, and Steven is correct. To affect domain accounts, the
_only_ place you can set account policy is at the domain level. Set it
any where else and all you're affecting is accounts in the local SAM of
any computers to which the GPO applies.

-- 
Paul Adare
Moral indignation is jealousy with a halo.
H. G. Wells, The Wife of Sir Isaac Harman


Relevant Pages

  • Re: Domain vs Local Security Policy
    ... You guys (Steven and Paul) are correct but I believe the OP ... but for logging onto machine specific accounts that remains irrelevant. ... >> own password policy and block the policy inheritance from ... To affect domain accounts, the ...
    (microsoft.public.win2000.security)
  • RE: Group Policy: multiple password policies in the same domain?
    ... > it under access to the GPO. ... The conflict only happens when both policies ... results in having the policy denied. ... > user accounts it affects be able to read it and have "apply ...
    (Focus-Microsoft)
  • Re: Password Policy Basics
    ... but assumed the POLICY would be applied to ALL ... so lcoal machines might start enforcing that policy on ... No, the local accounts are not effected by the domain policy, except you link the policy also to the OU like Florian states. ... I was thinking of service accounts on the servers... ...
    (microsoft.public.windows.group_policy)
  • Re: Windows 2000 users accounts get locked out
    ... I have disabled my accounts lockout policy in my ... >account logon events enabled in Domain Security Policy ... and Domain Controller ...
    (microsoft.public.win2000.security)
  • Re: AD 2000, Blank passwords, and Group Policy
    ... I set up an account with password policy enforced and experienced the same as you ... The only thing I can suggest is to leave the accounts as they ... accounts to change password at next logon. ... I could set the policy to not enforce this until after all ...
    (microsoft.public.win2000.security)