Re: GPO - password policy - Urgent



That is curious that you are having a problem with Windows 98 since I would
think Windows 98 would work with any password up to 14 characters but I
don't have a Windows 98 computer handy to try out such. I know that if you
disable storage of LM hashes you can have problems with Windows 98 computers
if you also enforced that recently in which is done via a security option
for Windows 2003 domain controllers in either Local Security Policy
[secpol.msc] or Domain Controller Security Policy or a registry entry for
Windows 2000 domain controllers. You may also have problems if you configure
lan manager authentication level security option to be too secure for domain
controllers such as use ntlmv2 only refuse lm or refuse lm and ntlm when
using Windows 98 computers in the domain. To disable password complexity you
set it to disabled in Domain Security Policy or whatever domain level GPO
that is applying password policy. The link below explains some of the
problems you can have with downlevel clients such as Windows 98 with certain
security option settings. So what I would do is to check lan manager
authentication level for domain controllers and make sure storage of lm
hashes is not disabled to see if that helps or not and check the KB article
for other possible incompatibilities and I really doubt it is related to
password complexity if the minimum password length is 7 characters and the
user is not trying to use a password over 14 characters. --- Steve

http://support.microsoft.com/default.aspx?scid=kb;en-us;823659
http://support.microsoft.com/default.aspx?scid=KB;EN-US;q299656 --- info
on disabling lm hash
http://support.microsoft.com/default.aspx?scid=kb;EN-US;q239869 --- lan
manager authentication level

"Fernando Mantovani" <femantovani@xxxxxxxxxxxx> wrote in message
news:eSWTKaBKGHA.312@xxxxxxxxxxxxxxxxxxxxxxx
I`m really desperate!!!

I have installed a new domain, with XP and 98 workstatioins. Everythings
works fine!

So, I changed the password policy to enable complexity with a minimum of 7
characters. Only after this I saw that 98 can`t use password complexity,
he
only accepts with dsclient.exe and a dword in the registry to force NTLMv2
authentication (I tried this too, but with this setting, I can`t log on
even
with the enterprise admin (that has temporarily a simple password)).

So, my problem is that I changed the default domain policy to disable
password complexity but I can`t change to a simple password in any users
of
my domain.

Is there a way to reset to "default" the default domain policy and the
default controller domain policy?

Someon has any ideas??

Tks!




.



Relevant Pages

  • Windows Shortcut Keys and "ALT+TAB" not working because of GPO
    ... We've got an issue with a machine policy which prohibits us of using Windows ... Deny access to this computer from the network Support_388945a0, ... Policy Setting ...
    (microsoft.public.de.german.windowsxp.gruppen.richtlinien)
  • domain users cant logon locally
    ... This is probably caused by the fact that your Windows 2000 ... To find this setting right click the DOmain Controllers OU ... Policy tab, verify that the Default Domain Controllers ... >I have recently installed a new windows 2000 server. ...
    (microsoft.public.win2000.security)
  • Re: Password requirements
    ... The default password-complexity settings in Windows 2000 are as follows: ... this setting is disabled in the Default Domain Group Policy ... Contains characters from three of the following four categories: ... Complexity requirements are enforced upon password change or creation. ...
    (microsoft.public.windows.server.active_directory)
  • Re: The local policy of this system does not permit you to log on interactively
    ... Configuration> Windows Settings> Security Settings> User Rights ... Assignment> here look for policy "Allow Logon Locally" and double click on ... This policy is to protect your domain controllers from any ordinary domain ...
    (microsoft.public.windows.server.general)
  • Re: Windows 2000 Auditing Object Access
    ... This is known problem if you use Windows XP SP2 to edit GP and then view the ... policy on a Win2000 DC. ... Windows Server 2003/2000/NT; CCA ... > One of the domain controllers is our File and Print server. ...
    (microsoft.public.windows.server.general)

Quantcast