Re: GPO not picking up computer settings




"Jarryd" <j@xxx> wrote in message
news:%23gTdtfJXGHA.1228@xxxxxxxxxxxxxxxxxxxxxxx
Hi Roger,

The user accounts are domain user accounts. I have removed the GPO that I
had configured with the password settings. So now there is only the
Default Domain Policy and the Default Domain Controllers Policy. I have
configured the Default Domain Policy so that the password settings are to
not Disable complexity, 0 history, 0 days to expiry, 0 minimum password
age, and 1 character minimum length. I have then done a GPUdpate on a DC.
No errors were logged in Event Viewer. However, I still can't change
password back to anything simple, e.g. "password". How is this still
possible? I am not sure that I follow what you said previously, but what
I think you are saying is that if I create a policy and link it to an OU
then the settings in that policy will only affect user accounts held in
the local user DB of machines in that OU, e.g. \\client1\user1 and not
\\domain\user1. So if you want to enforce settings on domain user
accounts you can't do so by adding/moving user accounts to an OU and
linking a GPO to that OU. You have to link it to the domain. But that
will affect all users, and I only want to apply these settings to users
that will be accessing the netword remotely. So do I add these users to a
security group, then remove the Authenticated users from the Security
Filtering list and add that newly created security group

No. You accept the fact that there is one Account policy and it is
applied equally to all domain account (without exception).
If some account must have different policies that is sometimes stated
as a design cause for a separate domain.

(making sure that have read and apply permissions?

TIA,

Jarryd


"Roger Abell [MVP]" <mvpNoSpam@xxxxxxx> wrote in message
news:ON1MaIlWGHA.1192@xxxxxxxxxxxxxxxxxxxxxxx
Those users are domain accounts or machine local accounts ??

"Jarryd" <j@xxx> wrote in message
news:eM248rYWGHA.3848@xxxxxxxxxxxxxxxxxxxxxxx
OK, I have managed to get the GP Management tool to pick up the settings
and it says that it is applying them in the way that I want them to on
the machine and user against which I ran the test. I went in to the
Local Policy and it has picked up the settings. But when I try to
change there password it lets me do it with less characters that
required, it is not picking up the history of old passwords, and it
isn't enforcing complexity. I really don't understand this.

Please help!!

Jarryd

"Jarryd" <j@xxx> wrote in message
news:e8T1EbYWGHA.5012@xxxxxxxxxxxxxxxxxxxxxxx
Hi,

I have created a Group Policy for remote users. The only settings I
have configured are the ones that pertain to passwords and account
lockout. I have moved those users to an OU that is linked to the new
GP, but the settings weren't taking affect. So I generated a report
and it came back saying the policy was empty. But that's just wrong.
If I go in and configure user settings those are picked up, but the
computer settings aren't. Why?

TIA,

Jarryd









.



Relevant Pages

  • Re: GPO Update Problem (SYSVOL access via UNC)
    ... Server Security and Auditing Policy ... This list only includes links in the domain of the GPO. ... The settings in this GPO can only apply to the following groups, users, ...
    (microsoft.public.win2000.group_policy)
  • Re: GPO Update Problem (SYSVOL access via UNC)
    ... > Server Security and Auditing Policy ... > This list only includes links in the domain of the GPO. ... > The settings in this GPO can only apply to the following groups, users, ...
    (microsoft.public.win2000.group_policy)
  • Re: GPO not picking up computer settings
    ... to the domain container with the password/account settings you want. ... for password/account settings and from what GPO. ... buying any of the highly rated AD or Group Policy books you see at Amazon or ... I have changed all the passwords back to what they were so users are now ...
    (microsoft.public.windows.server.security)
  • Re: Local GPO refreshes outside of refresh interval
    ... I looked through my GPO's Windows Settings section ... > Some policies, including IE policies, have a checkbox that defines if this ... > it should apply EVEN if the value defined in GPO did not change since the ... we are talking about one particular policy: ...
    (microsoft.public.windows.group_policy)
  • Re: IE Maintenance Group Policy Settings Issue
    ... If you configure a GPO to set the proxy to blank, ... be identified as a change to the policy and it will be re-applied to the ... This would be a GPO change and the settings ...
    (microsoft.public.win2000.group_policy)