Re: Account Lockout

From: Steven L Umbach (n9rou_at_nospam-comcast.net)
Date: 04/20/04


Date: Tue, 20 Apr 2004 16:39:59 GMT

Make sure you make the changes at the domain policy level, either at the default
domain policy or on the highest GPO in the list for the domain if you have more than
just the default domain GPO. In addition make sure that "block inheritance" is not
configured on the domain controller container. Running the "net accounts" command on
the domain controllers should display what the actual policy is. If you can not
resolve it, then you may have a replication problem within the domain possibly
relating to dns misconfiguration. Looking in Event Viewer on the domain controllers
will usually tell you that in addition to running dcdiag on one or more domain
controllers including the one you changed to policy on. Dcdiag and other extremely
helpful utilities are located on the install cdrom under the support/tools folder
where you have to run the setup there. --- Steve

"Mehdi Amini" <mehdi.amini@valueoptions.com> wrote in message
news:193901c426dc$038a9190$a301280a@phx.gbl...
> We have disabled our Account lockout policy but it becomes
> enabled after a few hours automatically. Has anyone seend
> this problem



Relevant Pages

  • Re: Default Domain password policy issue
    ... The domain controllers are members of authenticated users. ... as for applied Group Policy objects for computer settings. ... Policy replication/version problems. ... The settings in this GPO can only apply to the following groups, users, ...
    (microsoft.public.windows.group_policy)
  • Re: Blocking port scans on local network
    ... You can implement enumeration of SAM accounts and shares with probably no ... on domain controllers via Domain Controller Security Policy depending of ... domain computer that has a "require" ipsec policy assigned to it. ... between domain computers and domain controllers as the domain controllers ...
    (microsoft.public.win2000.security)
  • RE: Account Lockout Policy
    ... he didn't say that the policy would be *linked* at ... the Domain Controllers OU, just that the domain password policy would apply ... the Domain Controllers OU will still use the password policy that is defined ... they still utilize the domain-level account settings, because, again, the ...
    (Focus-Microsoft)
  • Re: Blocking port scans on local network
    ... > additional restrictions for anonymous connections in this security guide. ... > do not recommend applying ipsec policy wide scale without some testing of ... > between domain computers and domain controllers as the domain controllers ...
    (microsoft.public.win2000.security)
  • Re: Default Domain Policy Doesnt Apply
    ... Also to add that Group Policies are by default applied in this ... level will be overriden by any defined settings at the site, domain, OU ... account policies] are not being applied to the domain controllers since they ... > password and lockout policy can ony be set at the domain level for domain ...
    (microsoft.public.win2000.group_policy)