Re: domain security policy



Thanks Brian,

I found the following doc, is it safe to appy it to prevent "Administrator"
or some service a/c to appy those password policy.

http://support.microsoft.com/kb/315675

Thanks

Patrick


"Brian Komar (MVP)" wrote:

Some answers inline.
"Patrick" <Patrick@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:F49EB9FC-BD85-4504-A0A0-E48994398E56@xxxxxxxxxxxxxxxx
Thanks all your help.

I want to setup a security policy on Windows 2000 domain environment to
enforce general user to change their password every 3 months and something
like enforce password history, a/c lock out.

I have the following question:
- Is it applied to all domain users inclued "Domain Administrator"?

Yes, unless there is a specific account setting override
- How can exclude some of users like "Domain Administrator" and some
services a/c of above setting?

Yes, for the specific account, you can choose to prevent the requirement to
change passwords. But, if you set up complexity, etc, then it must be
followed.

- If I set these policy in a new created OU level and move geneal user
computer object to this OU (not server and DC object), am I right that the
policy will only apply to these computer.

Nope. Account policy is domain wide in a Windows 2000 (and 2003) domain. It
applies to *all* users in the domain.

- What is the best prastice to apply these domain security setting?

Like you are doing.


Thanks for your help.

Patrick




.



Relevant Pages

  • Re: Must all users be administrators?
    ... The familiar look of the AD objects tree you see in Group Policy Editor is ... This seems modestly confusing to an SBS Administrator because there's very ... those rights happen to be nearly unlimited. ... sit a workstation logged on as the Local Administrator, by default, there ...
    (microsoft.public.windows.server.sbs)
  • Re: The local policy of this system does not permit you to logon i
    ... Security policies were propagated with warning. ... Error 0x534 occurs when a user account in one or more Group Policy objects ... I have checked the security policies & the administrator profile is not ...
    (microsoft.public.windows.server.sbs)
  • Re: Administrator unable to log on Interactively
    ... Firstly i tried accessing the domain controller C drive ... I think the policy has been changed in the "local security ... >> administrator is not able to log on interactively. ... >Interactive Logon setting takes precedence over the Allow ...
    (microsoft.public.win2000.security)
  • Re: Administrator is not the "Boss" on this machine.
    ... policy, I'd see two columns, one for "setting" ... > you can not run that command you may not be logged on as an administrator. ... > If you messed with Group Policy settings for user configuration the solution above ...
    (microsoft.public.win2000.security)
  • Event 1202 Warnings after Renaming Administrator Acct on SBS2003
    ... one referencing the original administrator account: ... specific policy setting that was flagged with a big, ... I used an incorrect procedure to rename the ...
    (microsoft.public.windows.server.general)