Re: GPO questions

Tech-Archive recommends: Fix windows errors by optimizing your registry



That is not entirely true. You must make the distinction between "domain"
users and "local" computer users on domain computers. You can define
password/account policy at the OU level but it will apply ONLY to local
users on domain computer within the scope of management of that OU. In such
case block inheritance at the OU would mean that the password/account policy
settings defined in Local Security Policy of the domain computers in that OU
would apply to the local users on those domain computers - not what is
configured at the domain level.

Why does this all matter? Well maybe you would want to have different
password/account policy for the local computer accounts in the domain many
of which may only contain the built in administrator account and the guest
account which would be disabled by default. The local administrator account
on a domain computer while not all powerful in the domain certainly is an
important account on sensitive domain computers such as the Enterprise
Certificate Authority or any other important computers. --- Steve


"Wayne" <Wayne@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:290AAF2D-26B8-47E0-AF67-BFEA23ED8A7E@xxxxxxxxxxxxxxxx
> Hi,
> I am going through a Transcender for 70-217, and it states "When a
> password
> policy is set at the domain level and the Block Policy Inheritance option
> is
> enabled at the OU level, the password policy overrides the enabled block
> policy inheritance option." I though you would have to set the no
> override
> option at the higher lever GPO for this action to take place. Any other
> got-ya's ?
> Thanks - Wayne


.



Relevant Pages

  • Re: Password Policy
    ... Yes they do unless you have moved any domain computers into another ... computers in that OU could apply to local user accounts on those ... > do domain policies override local policies as a rule? ...
    (microsoft.public.win2000.group_policy)
  • Re: install printers based on the active directory OU by pushing a machine startup script
    ... Alan Bastanpour schrieb: ... The access denied message is coming from the local ... It appears the "Domain Computers" account doesn't have enough ...
    (microsoft.public.windows.group_policy)
  • Re: auditing
    ... You would have to enable auditing of logon events for domain machines. ... to only enable auditing of failures on domain computers that are not resource ... logon attempts using your account. ...
    (microsoft.public.win2000.security)
  • Re: what is that best way to install program?
    ... You are correct in your concern about using a domain admin account. ... opinion a domain administrator should never logon to a domain computer that ... administrators group on domain computers in that OU. ...
    (microsoft.public.windows.server.security)
  • Re: Authenicated Users Query
    ... If the account that the user is logged onto on the non domain computer has ... If you have auditing of logon events enabled ... use ipsec AH/ESP for communications with domain computers but otherwise it ...
    (microsoft.public.windows.server.security)