I like this response, and Webster’s better. I found a policy that is called Default Domain Policy1. Unfortunately, it is not linked to anything. I will try to create a new policy, linking it at the domain level, and apply only these password policies, and let you guys know how it turns out. I’m not liking whatever was done before I got here as far as GP goes…
Is there anything else that is set by default by the Default Domain Policy? Seeing as how we don’t actually have a working one here… Joe Heaton Employment Training Panel From: Ken Schaefer [mailto:[EMAIL PROTECTED] Sent: Saturday, October 25, 2008 1:28 AM To: NT System Admin Issues Subject: RE: Password policy Incorrect. The policy must be linked at the domain level (Win2k3 and earlier). Doesn’t have to be in the Default Domain Policy. Best practise is not to edit the Default Domain policy. That way, if you do stuff something up, you can always unlink your new policy, and Microsoft’s default will kick back in. Cheers Ken From: Robert Cato [mailto:[EMAIL PROTECTED] Sent: Saturday, 25 October 2008 9:27 AM To: NT System Admin Issues Subject: Re: Password policy Yes, password changes only are affected by the default domain policy. On Fri, Oct 24, 2008 at 6:15 PM, Joe Heaton <[EMAIL PROTECTED]> wrote: Are you saying I have to do this in the default domain policy? Do I set it at the same point within? Joe Heaton Employment Training Panel From: Carl Houseman [mailto:[EMAIL PROTECTED] Sent: Friday, October 24, 2008 3:13 PM To: NT System Admin Issues Subject: RE: Password policy Password policies are set at the domain level, assuming 2003 or earlier. You can't get there from here unless you create a new domain for those 27 people. Carl From: Joe Heaton [mailto:[EMAIL PROTECTED] Sent: Friday, October 24, 2008 6:10 PM To: NT System Admin Issues Subject: Password policy This may be a stupid question, but my google-fu is just giving me generic answers. I want to enforce some password requirements, that are not in effect now. I've done this by creating a new group policy, at the top level of my user OUs. I've gone into Computer configuration -> Windows settings -> Security settings -> Account policies -> Password policy. I set the minimum length, etc. Then, in the right side window for the GPO in GPMC, I use Security filtering to apply the policy to one specific user, for testing. I then went into that user's account, and checked the box for must change password. Then, I go to the machine where I have this user account logged in, go to command prompt and type in gpupdate /force, reboot the machine, and go to change the password. To test it, I tried using a very short password, and it was allowed. What am I doing wrong here? I've got 27 new computers rolling out tomorrow, and we want to enforce the password stuff for those 27 people, but I need to get this right. Joe Heaton AISA Employment Training Panel 1100 J Street, 4th Floor Sacramento, CA 95814 (916) 327-5276 [EMAIL PROTECTED] ~ Finally, powerful endpoint security that ISN'T a resource hog! ~ ~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/> ~
