Re: Password Policy - Effective Settings

From: Steven L Umbach (n9rou_at_nospam-comcast.net)
Date: 04/07/05


Date: Thu, 7 Apr 2005 13:47:22 -0500

For domain users you can only configure password policy at the domain level.
You can however configure different settings to a domain computer and it
will apply to local user accounts on that domain computer. If your two
servers are in the same container/OU then they should have the same
effective settings assuming default permissions to the GPO that is being
applied [no filtering]. A better way to refresh policy is with " secedit
/refeshpolicy machine_policy /enforce ". If you are still having problems
run the support tool gpresult to see that list of computer configuration
policies being applied to each computer and the last time they were applied.
Then run the netdiag support tool on the problem server to make sure it is
correctly configured for the domain and that it has no network connectivity
problems. You will also see an Event ID 1704 in the application log of a
computer indicating that security policy has been refreshed and the time it
was refreshed. --- Steve

http://support.microsoft.com/kb/227302

"Murali.A" <MuraliA@discussions.microsoft.com> wrote in message
news:DCA70A81-7F74-49AF-B64D-B7F829B329B7@microsoft.com...
> Hi All,
> I have two W2k servers and they are configured to my Domain server.
>
> Server 1:
> I am able to change the Security Settings - > Password Policy -> "Password
> must meet complexity requirement" property value. At this time if I see
> the
> values of
> Local Settings and Effective Settings are different. After that if I do
> the
> action Security Settings Right Click, Reload then Local Setting values is
> overlayed to the Effective settings.
>
> Server 2:
> I am able to change the Security Settings - > Password Policy -> "Password
> must meet complexity requirement" property value. At this time if I see
> the
> values of
> Local Settings and Effective Settings are different. After that if I do
> the
> action Security Settings Right Click, Reload then Local Setting values is
> not
> overwriting the Effective settings. Means I am able to set different
> values
> to Local and Effective setings.
>
> Question:
> 1. Why Server1 is not working the same way Server2? Please advice.
> 2. Which Server is working correctly in Group Policy Scenario?
> 3. I am expecting the below command always export the value shown in the
> Effectiv Settings. Am I correct?
> (Because in Server1 I can not capture the 2 setting with different values
> so
> from the command result I can not say which one it is reading). Please
> advice.
> %SystemRoot%\system32\secedit.exe /export /mergedpolicy /cfg dump.inf
> /areas
> SECURITYPOLICY /quiet
>
> Advance Thanks,
>
> Murali.



Relevant Pages

  • Re: Userenv Event ID 1054
    ... Did you add the slow link item to you policy or make another GPO ... To disable slow link detection on the SBS Server, ... please refer to the following settings to modify the ...
    (microsoft.public.windows.server.sbs)
  • Re: W32 time problem on SBS2003 Premium
    ... That other server isn't really so odd. ... then group policy isn't being applied and your manual settings will be used. ... >> have settings for Enable NTP Client, Configure NTP Client, and Enable NTP ...
    (microsoft.public.windows.server.sbs)
  • Re: Inherited security properties
    ... group policy set on the organizational until that your server is in. ... settings at the local policy level. ... > When I look at the local security policy on the Windows ...
    (microsoft.public.win2000.security)
  • RE: Please help - with the portal server
    ... LAN settings - i was wondering may be - sps uses certain ports to communicate ... with the server over the internet. ... microsoft.sharepoint.portal.dll security permission grant set is incompatible ... Use Group Policy to Add the Sites ...
    (microsoft.public.sharepoint.portalserver)
  • Re: SBS DCOM
    ... On the server I was afraid to delete them ... (and I can now change policy settings and access DCOM and WMI ... |> steps to reset the group policy objects to default, ...
    (microsoft.public.windows.server.sbs)