I like this response, and Webster’s better.  I found a policy that is called 
Default Domain Policy1.  Unfortunately, it is not linked to anything.  I will 
try to create a new policy, linking it at the domain level, and apply only 
these password policies, and let you guys know how it turns out.  I’m not 
liking whatever was done before I got here as far as GP goes…

 

Is there anything else that is set by default by the Default Domain Policy?  
Seeing as how we don’t actually have a working one here…

 

Joe Heaton

Employment Training Panel

 

From: Ken Schaefer [mailto:[EMAIL PROTECTED] 
Sent: Saturday, October 25, 2008 1:28 AM
To: NT System Admin Issues
Subject: RE: Password policy

 

Incorrect. The policy must be linked at the domain level (Win2k3 and earlier). 
Doesn’t have to be in the Default Domain Policy.

 

Best practise is not to edit the Default Domain policy. That way, if you do 
stuff something up, you can always unlink your new policy, and Microsoft’s 
default will kick back in.

 

Cheers

Ken

 

From: Robert Cato [mailto:[EMAIL PROTECTED] 
Sent: Saturday, 25 October 2008 9:27 AM
To: NT System Admin Issues
Subject: Re: Password policy

 

 

Yes, password changes only are affected by the default domain policy.

On Fri, Oct 24, 2008 at 6:15 PM, Joe Heaton <[EMAIL PROTECTED]> wrote:

Are you saying I have to do this in the default domain policy?  Do I set it at 
the same point within?

 

Joe Heaton

Employment Training Panel

 

From: Carl Houseman [mailto:[EMAIL PROTECTED] 
Sent: Friday, October 24, 2008 3:13 PM 


To: NT System Admin Issues

Subject: RE: Password policy 

 

Password policies are set at the domain level, assuming 2003 or earlier. 

You can't get there from here unless you create a new domain for those 27 
people.

 

Carl

 

From: Joe Heaton [mailto:[EMAIL PROTECTED] 
Sent: Friday, October 24, 2008 6:10 PM
To: NT System Admin Issues
Subject: Password policy

 

This may be a stupid question, but my google-fu is just giving me generic 
answers.

 

I want to enforce some password requirements, that are not in effect now.  I've 
done this by creating a new group policy, at the top level of my user OUs.  
I've gone into Computer configuration -> Windows settings -> Security settings 
-> Account policies -> Password policy.  I set the minimum length, etc.  Then, 
in the right side window for the GPO in GPMC, I use Security filtering to apply 
the policy to one specific user, for testing.  I then went into that user's 
account, and checked the box for must change password.  Then, I go to the 
machine where I have this user account logged in, go to command prompt and type 
in gpupdate /force, reboot the machine, and go to change the password.  To test 
it, I tried using a very short password, and it was allowed.

 

What am I doing wrong here?  I've got 27 new computers rolling out tomorrow, 
and we want to enforce the password stuff for those 27 people, but I need to 
get this right.

 

Joe Heaton

AISA

Employment Training Panel

1100 J Street, 4th Floor

Sacramento, CA  95814

(916) 327-5276

[EMAIL PROTECTED]

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/>  ~

Reply via email to