Re: Windows 2003 domain password policy



There is only one password policy per domain, always set in a GPO
linked to the domain object.

If you need different policies within one domain you would need to
have a custom Gina in use. For some cases where people do want
different policies, use of required smart card login for the few for
which higher password control was desired can turn out to be a
usable alternative.

Personally, I like to leave the two default GPOs alone, implementing
policy via newly defined GPOs (not necessarily defined for just some
singular purpose). This allows reset of the default GPOs without
concern of that action's impact. The use or not of the default GPOs
to carry custom policy settings is likely, largely a stylistic preference.

"John Smith" <nzsms@xxxxxxxxxxx> wrote in message
news:eJ4hJfd4GHA.3556@xxxxxxxxxxxxxxxxxxxxxxx
Can we have 2 sets of domain password policy? Or we can use Block Policy
Inheritance and Disable No Override option to achieve this.

Any suggestion for best Domain Password Policy pratice? Modify the default
Domain Policy GPO or create a new Password GPO and linked to the root
container?

If we implement a secure password policy now, what may happen to the
existing users? Are they offered a chance to change their password when
they
first log in? How about those laptop mobile VPN users?



.



Relevant Pages

  • Re: _Group Policy only 1 of 6 is working
    ... Additional: This AM GPUpdate is now showing the 5 GPOs as "filtering: ... I'm really beginning to dislike group policies. ... >Account Policies / Password Policy ... >Computer Configuration. ...
    (microsoft.public.win2000.group_policy)
  • Re: _Group Policy only 1 of 6 is working
    ... If you have 6 GPOs applied to one OU, all with Password policies, then you ... > All of the GPOs do have settings, specifically the password policy I ... >>> 2 DCs ...
    (microsoft.public.win2000.group_policy)
  • Re: Multiple password policies for ONE domain?
    ... and the last password policy evaluated will "win". ... You can only have one account policy at the domain level. ... password policies for one domain? ... If multiple GPOs could be used, what will be the behavior of having 2-3 ...
    (microsoft.public.windows.server.active_directory)
  • Re: How to ... 2nd request
    ... > I appreciate your clarification and views on my answer Glenn. ... >> OUs and GPOs, ... >> There are two policies you can set to acheive the desired results. ... >> the workstations will not revert back to their default state. ...
    (microsoft.public.windows.server.general)
  • Re: How to ... 2nd request
    ... > I appreciate your clarification and views on my answer Glenn. ... >> OUs and GPOs, ... >> There are two policies you can set to acheive the desired results. ... >> the workstations will not revert back to their default state. ...
    (microsoft.public.windows.server.active_directory)