Re: Blank Passwords, Complex Requeirements and Problems...

Tech-Archive recommends: Fix windows errors by optimizing your registry



Hello,

Are you sure that those accounts are subject to the group policy?
I recommend running a "Resultant Set of Policies" test on the user accounts
in question.
There are several reasons why a given policy will not be applied to a user
account. I would find out first if the policy is being applied to those
accounts or not. If it is not, then you need to track down why the accounts
are exempt.

--
Ken Aldrich
DSRAZOR for Windows
Visual Click Software, Inc.
www.visualclick.com

"MCTS" <MCTS@xxxxxxxx> wrote in message
news:EEDCD917-1BD0-457F-8434-F9F6BAB0D5D2@xxxxxxxxxxxxxxxx
Blank Passwords, Complex Requeirements and Problems...

An auditor discovered several accouns with Blank Passwords in a
MultiDomain AD structure arround the world

As far as i know, the Win2003 AD never had a "free" Default Domain Policy
to allow that, the DDP is the Default since the initial build of th AD.
Ok, let's say that an Admin disabled temporarily th DDP for a few moments
and allowed certain accouns to be created with blank passwords. Today, the
DDP is configured to allow only complex passwords.

10 accounsts in the domain (among 1.200 other accounts) were found with
blank passwords. When we reset thoses passwords, the ADUC allows.. BLANK
passwords!!!!! Only in the 10 aaccounts created in 2007 (The AD was
created on 2004). Any other user don't have that problem, only a
sequencial list of accounts (created by script with the DSADD tool,
exactly like any other account in the domain)







.



Relevant Pages

  • Re: Sharing folder permission ????
    ... XP blocks network access to accounts that have blank ... you can do so through Local Security Policy. ... Limit local account use of blank passwords to ... When I click my Xp system visible in default>>woprkgroup, I get a login windows whcih identify me on> the ...
    (microsoft.public.windowsxp.security_admin)
  • Re: password expiration policy for admin and system accounts ?
    ... policy that Admins manually reset these important account passwords every ... You can still have the passwords set to never expire, ... > Privileged accounts should be the most, not the least, well guarded. ...
    (microsoft.public.security)
  • Re: password expiration policy for admin and system accounts ?
    ... policy that Admins manually reset these important account passwords every ... You can still have the passwords set to never expire, ... > Privileged accounts should be the most, not the least, well guarded. ...
    (microsoft.public.win2000.security)
  • RE: Group Policy: multiple password policies in the same domain?
    ... > it under access to the GPO. ... The conflict only happens when both policies ... results in having the policy denied. ... > user accounts it affects be able to read it and have "apply ...
    (Focus-Microsoft)
  • Re: Password Policy Basics
    ... but assumed the POLICY would be applied to ALL ... so lcoal machines might start enforcing that policy on ... No, the local accounts are not effected by the domain policy, except you link the policy also to the OU like Florian states. ... I was thinking of service accounts on the servers... ...
    (microsoft.public.windows.group_policy)