If you have backups, that is the recommended way to restore it. If you
must re-create it- 

 

Recreatedefpol.exe in 2000, Dcgpofix.exe in 2003 & 2008. Caveat
emptor...

 

The Dcgpofix tool is intended for use only as a last-resort
disaster-recovery tool. To create regular backups of the default domain
and all other GPOs, you must use Group Policy Management Console (GPMC).
It is also recommended that you backup the Sysvol directory with a
regularly scheduled backup procedure.

 

From: Devin Meade [mailto:[EMAIL PROTECTED] 
Sent: Monday, October 27, 2008 8:38 AM
To: NT System Admin Issues
Subject: Re: Password policy

 

FYI

If you need to restore the def domain policy, I **think** there is a way
to restore it.  I remember this from somewhere.  You might explore that
if needed.  

 

hth-Devin

On Mon, Oct 27, 2008 at 9:57 AM, Joe Heaton <[EMAIL PROTECTED]> wrote:

Thanks for all the help guys, I created a new Domain Password Policy,
and it is in effect, according to a Group Policy Results query.

 

Joe Heaton

Employment Training Panel

 

From: James Rankin [mailto:[EMAIL PROTECTED] 
Sent: Monday, October 27, 2008 7:24 AM 


To: NT System Admin Issues
Subject: Re: Password policy

 

I think it disables RIS, sets password policy, account lockout policy,
Kerberos poluicy, public key policies, and some local security options

2008/10/27 Joe Heaton <[EMAIL PROTECTED]>

I like this response, and Webster's better.  I found a policy that is
called Default Domain Policy1.  Unfortunately, it is not linked to
anything.  I will try to create a new policy, linking it at the domain
level, and apply only these password policies, and let you guys know how
it turns out.  I'm not liking whatever was done before I got here as far
as GP goes...

 

Is there anything else that is set by default by the Default Domain
Policy?  Seeing as how we don't actually have a working one here...

 

Joe Heaton

Employment Training Panel

 

From: Ken Schaefer [mailto:[EMAIL PROTECTED] 
Sent: Saturday, October 25, 2008 1:28 AM


To: NT System Admin Issues
Subject: RE: Password policy

 

Incorrect. The policy must be linked at the domain level (Win2k3 and
earlier). Doesn't have to be in the Default Domain Policy.

 

Best practise is not to edit the Default Domain policy. That way, if you
do stuff something up, you can always unlink your new policy, and
Microsoft's default will kick back in.

 

Cheers

Ken

 

From: Robert Cato [mailto:[EMAIL PROTECTED] 
Sent: Saturday, 25 October 2008 9:27 AM


To: NT System Admin Issues

Subject: Re: Password policy

 

 

Yes, password changes only are affected by the default domain policy.

On Fri, Oct 24, 2008 at 6:15 PM, Joe Heaton <[EMAIL PROTECTED]> wrote:

Are you saying I have to do this in the default domain policy?  Do I set
it at the same point within?

 

Joe Heaton

Employment Training Panel

 

From: Carl Houseman [mailto:[EMAIL PROTECTED] 
Sent: Friday, October 24, 2008 3:13 PM 


To: NT System Admin Issues

Subject: RE: Password policy 

 

Password policies are set at the domain level, assuming 2003 or earlier.


You can't get there from here unless you create a new domain for those
27 people.

 

Carl

 

From: Joe Heaton [mailto:[EMAIL PROTECTED] 
Sent: Friday, October 24, 2008 6:10 PM
To: NT System Admin Issues
Subject: Password policy

 

This may be a stupid question, but my google-fu is just giving me
generic answers.

 

I want to enforce some password requirements, that are not in effect
now.  I've done this by creating a new group policy, at the top level of
my user OUs.  I've gone into Computer configuration -> Windows settings
-> Security settings -> Account policies -> Password policy.  I set the
minimum length, etc.  Then, in the right side window for the GPO in
GPMC, I use Security filtering to apply the policy to one specific user,
for testing.  I then went into that user's account, and checked the box
for must change password.  Then, I go to the machine where I have this
user account logged in, go to command prompt and type in gpupdate
/force, reboot the machine, and go to change the password.  To test it,
I tried using a very short password, and it was allowed.

 

What am I doing wrong here?  I've got 27 new computers rolling out
tomorrow, and we want to enforce the password stuff for those 27 people,
but I need to get this right.

 

Joe Heaton

AISA

Employment Training Panel

1100 J Street, 4th Floor

Sacramento, CA  95814

(916) 327-5276

[EMAIL PROTECTED]

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 




-- 
Devin

 

 

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/>  ~

Reply via email to