Re: Password Policies

From: Danny Sanders (Danny.Sanders_at_NO-SPAMcpcmed.org)
Date: 06/09/05


Date: Thu, 9 Jun 2005 14:19:20 -0600

Account policies are one to a domain. Account policies applied at the OU
level only take affect when the user logs onto a computer in that OU
locally.

On a domain with information sensitive enough to require "strong" passwords,
setting some users with "simple" password amounts to the domain admin
creating a security hole.

Differing password requirements is one major reason for creating another
domain.

hth
DDS W 2k MVP MCSE

"Rene Heroux" <ReneHeroux@discussions.microsoft.com> wrote in message
news:FE9290CF-5D8D-47B5-ABC1-5F56D31C7E72@microsoft.com...
> I've organized my Active Directory into various OUs, and one of them is
> called Remote Users.
>
> If I create a GPO for this OU and check the Block Policy Inheritance
> checkbox, would this mean that the computers in the Remote Users OU would
> be
> excluded from the sitewide Password Policy rules as defined in the Default
> Domain Policy?
>
> I'm just trying to figure out someway around this restriction... as most
> of
> you probably know salesmen are hard enough to deal with on a day-to-day
> basis
> without giving them yet another task to do. (And yeah, it should be easy
> enough but you should see some of the calls I get sometimes, heh.)



Relevant Pages

  • Re: Security Policy for OU?
    ... The DCs pull this info. from the domain; not from a specific linked GPO ... Assuming that the policy can be linked, my question is based on Ulf's assertion that: "The account policies for domain users only apply if they are in the default domain policy." ... > be recreated in the default domain policy of the child domain? ...
    (microsoft.public.windows.server.active_directory)
  • Re: Maximum password age
    ... At what level did you check for the Account Policies ie using RSOP ... So open the Default Domain Policy from AD Users and Computers, ... > Gautam Anand ... > | When I originally set securitry settings I didn't change the maximum ...
    (microsoft.public.windows.group_policy)
  • Re: Problem with Group Policies
    ... Account Policies is at the GPO linked to the domain, ... with some settings not being applied from a Default Domain Policy. ... I have created a Default Domain Policy at the root Domain and have applied ...
    (microsoft.public.win2000.group_policy)
  • Questions about domain password policies
    ... I have a couple of questions about domain password policies. ... Understanding that account policies must be applied at the domain ... If management requests that the implementation of a password policy ... if userA set his password in January of 2001 and ...
    (microsoft.public.windows.group_policy)
  • Re: Preventing logon to local accounts
    ... good idea if you have a lot of remote users. ... is activley a member of 2 groups, RDP's and Desktop users (desktop users is ... the policy I have been working on to customize the domain PC's). ...
    (microsoft.public.windows.server.active_directory)