Ok, I’ve set what I want within the default domain policy now. Since our accounts are actually setup to not expire, then all I should have to do is to uncheck that box, check the must change password, and they should be under the new requirements, right?
Joe Heaton Employment Training Panel From: Robert Cato [mailto:[EMAIL PROTECTED] Sent: Friday, October 24, 2008 3:27 PM To: NT System Admin Issues Subject: Re: Password policy Yes, password changes only are affected by the default domain policy. On Fri, Oct 24, 2008 at 6:15 PM, Joe Heaton <[EMAIL PROTECTED]> wrote: Are you saying I have to do this in the default domain policy? Do I set it at the same point within? Joe Heaton Employment Training Panel From: Carl Houseman [mailto:[EMAIL PROTECTED] Sent: Friday, October 24, 2008 3:13 PM To: NT System Admin Issues Subject: RE: Password policy Password policies are set at the domain level, assuming 2003 or earlier. You can't get there from here unless you create a new domain for those 27 people. Carl From: Joe Heaton [mailto:[EMAIL PROTECTED] Sent: Friday, October 24, 2008 6:10 PM To: NT System Admin Issues Subject: Password policy This may be a stupid question, but my google-fu is just giving me generic answers. I want to enforce some password requirements, that are not in effect now. I've done this by creating a new group policy, at the top level of my user OUs. I've gone into Computer configuration -> Windows settings -> Security settings -> Account policies -> Password policy. I set the minimum length, etc. Then, in the right side window for the GPO in GPMC, I use Security filtering to apply the policy to one specific user, for testing. I then went into that user's account, and checked the box for must change password. Then, I go to the machine where I have this user account logged in, go to command prompt and type in gpupdate /force, reboot the machine, and go to change the password. To test it, I tried using a very short password, and it was allowed. What am I doing wrong here? I've got 27 new computers rolling out tomorrow, and we want to enforce the password stuff for those 27 people, but I need to get this right. Joe Heaton AISA Employment Training Panel 1100 J Street, 4th Floor Sacramento, CA 95814 (916) 327-5276 [EMAIL PROTECTED] ~ Finally, powerful endpoint security that ISN'T a resource hog! ~ ~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/> ~
