Re: GPO configuration



I am still confused on this issue. What if I leave the domain
account/password policy undefined and apply different OU account/password
policies? It seems like this should work. Also on the issue of overrides -
does an account/password policy applied at the domain level override OU
level? I thought the lower GPO policies would overwrite the upper levels if
the same setting is configured with different parameters. So in my question
above the undefined policy would override the defined policy? Do
account/password policies always override lower processed GPO policies even
if you do not no override in the GPO? Note - these questions apply to 2000
arena - 70-217.
Thanks

"Steven L Umbach" wrote:

> Within the native operating system there can be only one password/account
> policy for "domain" users and this is defined only at the domain level. The
> domain controllers apply password policy and they read the policy from the
> winning domain level policy that has password policy defined which in a
> fresh install would be Domain Security Policy. However any domain linked GPO
> could apply the password policy and the GPO at the top of the list has
> highest priority. When configuring a password/account policy make sure that
> you do not change defined settings to "undefined" to reverse or disable
> them. A good example is password complexity. If you want to disable it for
> some reason change the domain level policy to disabled and not undefined as
> undefined will not disable it.
>
> There are ways to use custom passfilt.dll to have different password
> policies for different users/computers in a domain. Writing and installing a
> passfilt.dll correctly is not a trivial matter and takes a good programmer
> and there are third party applications that can do such. In my opinion it
> makes sense to have a strong password/account policy for all domain users
> and to train users how to conform to it. Training users to use pass phrases
> instead of passwords can help immensely. Instead of remembering T65r)*xn as
> a password they could use a favorite phrase such as A spoonful of sugar!
> which is a long complex password. Train them to leave the spaces in the
> passphrase. For sensitive accounts consider using smart cards and
> configuring the user account to require a smart card for logon.
>
> In Windows 2000/2003 domains are NOT security boundaries - forests are. You
> can create external or possibly forest trusts [in Windows 2003] to allow
> resources to users from a different forest. Remember that admins in the root
> forest domain are all powerful in a forest. --- Steve
>
>
> "Wayne" <Wayne@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
> news:79A7C1D9-7FD0-44A2-86C2-3E86D264F2DB@xxxxxxxxxxxxxxxx
> > Hi,
> > I am confused on the issue of Domains and security boundries. Can I have
> > different password policies in the same domain? Couldn't I have one policy
> > that has a 6 character password requirement and link it to a GPO for the
> > general user, and then have a 12 character password requirement for admin
> > group linked through a GPO? Also what happens when you have a GPO like
> > this
> > with password requirements linked to a site that crosses domains? Does it
> > just not process or execute properly?
> > Thanks - Wayner
>
>
>
.



Relevant Pages

  • Re: Local GPO refreshes outside of refresh interval
    ... I looked through my GPO's Windows Settings section ... > Some policies, including IE policies, have a checkbox that defines if this ... > it should apply EVEN if the value defined in GPO did not change since the ... we are talking about one particular policy: ...
    (microsoft.public.windows.group_policy)
  • Re: "There are 0 filters" using IPSec via GPO
    ... 1)Deleting all IPSec policies in the GPO ... 4)Assigning "request security" policy in Local Security Settings, ...
    (microsoft.public.win2000.security)
  • Re: Windows 2003 Server - Group Policy
    ... Group Policies refresh time is 90-minute intervals by default. ... For Windows 2000 Computers see the follow KB: ... Policy Inheritance can be set to this OU it means no policies from higher ... You can also set No Override to a particular GPO. ...
    (microsoft.public.win2000.active_directory)
  • Local GPO refreshes outside of refresh interval
    ... We are experiencing an unique situation where local group ... we are talking about one particular policy: ... a homepage on users and therefore, we never set this policy on the AD GPO. ... Even though we knew that group policies are refreshed every 90 minutes on ...
    (microsoft.public.windows.group_policy)
  • RE: Group Policy: multiple password policies in the same domain?
    ... > it under access to the GPO. ... The conflict only happens when both policies ... results in having the policy denied. ... > user accounts it affects be able to read it and have "apply ...
    (Focus-Microsoft)