RE: Block Policy Inheritance not working as anticipated

anonymous_at_discussions.microsoft.com
Date: 07/20/04


Date: Tue, 20 Jul 2004 07:57:35 -0700

have oyu got no override selected? if so uncheck it
>-----Original Message-----
>After posting this question I browsed other posts relevant
to my own and found my answer:
>
>Password policies are per domain only. This ensures that a
domain will have a consistent policy across all users, thus
not putting it at risk by allowing possibly weaker
passwords in a portion of the domain.
>
>It would appear that there is no way around this. If
there happens to be a solution, I would appreciate hearing
about it.
>
>Thanks!!!
>
>
>
>"bottomfeeder" wrote:
>
>> I have a Domain Controller running Windows 2000 Server.
 The Domain container (root) has a GPO (Default Domian
Policy) with password policies defined (complexity,
history, length and age). Below the Domain container I
have 3 OUs (Accounts, Domain Controllers and Groups). Only
the Domain Controllers OU has it's own GPO (Default Domain
Controllers Policy). This policy does not have any
password policies defined.
>>
>> Below the Accounts OU I have a child OU (EM Mailbox)
that contains User accounts. I have one GPO set for this
OU which does not have any password policies defined. I
have selected the check box for "Block Policy Inheritance"
under the Group Policy tab of the EM Mailbox properties.
>>
>> I expected this to block the password policy settings
from GPO on the Domain Container (root), but it has not
worked. On the Domain Controller I have issued the
following command after selecting the Block Policy
Inheritance check box:
>>
>> secedit /refreshpolicy machine_policy /enforce
>>
>> I also restarted the Domain Controller after issueing
the secedit command above.
>>
>> I am still unable to create a new user account in the EM
Mailbox OU without being subject to the password policies
set in the GPO associated with the Domain Container (root).
 I need to be able to create the new user account using a
password that does not meet all the password requirements
set in the Domain Container's GPO.
>>
>> Does anyone have any suggestions?
>>
>> Thanks in advance!!
>.
>



Relevant Pages

  • Re: GPO - Access denied after changing a GP setting
    ... You are about to restore Default Domain policy and Default domain Controller po ... This may render some server applications to fail. ... Unable to open the GPO due to access denied. ... You are about to restore Default Domain controller policy for the following domain ...
    (microsoft.public.windows.server.security)
  • Re: GPO - Access denied after changing a GP setting
    ... This may render some server applications to fail. ... y Unable to open the GPO due to access denied. ... This tool was unable to re-create the EFS Certificates in the Default D omain Policy GPO Access is denied. ... You are about to restore Default Domain controller policy for the following domain Do you want to continue: ...
    (microsoft.public.windows.server.security)
  • Re: Help with GPO problem!! PLEASE!!
    ... > Reposting as we tried in the GPO thread, but after an exhausted attempt, I ... I am racking my brain on this problem with a Windows 2003 Standard ... > Controller Security Policy or the GPO. ... > Domain Controller Security Policy: Failed to open the Group Policy Object. ...
    (microsoft.public.windows.server.active_directory)
  • Adding GPOs to Default Domain Controllers Policy
    ... In an effort to setup this GPO, I attempted to edit the Default Domain ... Controllers Policy Object by adding the firewall configuration settings ... While the adjusted policy did get applied to the "primary" DC where I ran ... Is adding this type of addition to the Default Domain Controller Policy ...
    (microsoft.public.windows.group_policy)
  • Re: Password never gets saved in IE7.0 in Win XP Pro
    ... I manage the domain controller as well, as far as I know we never applied ... any policy for user at IE. ... When I logon as administrator to the same ... When I logon using domain user account (please note this domain user does ...
    (microsoft.public.windowsxp.general)