Re: Applying password policies

From: Torgeir Bakken \(MVP\) (Torgeir.Bakken-spam_at_hydro.com)
Date: 08/02/04


Date: Mon, 02 Aug 2004 18:30:44 +0200

The Rock wrote:

> From what I have read from Microsoft, Account Policies
> which include the Password Policies can be applied to
> OUs. If that is the case can't I remove the Password
> Policies from the Domain Policy and apply them to all OUs?
> ----
> http://www.microsoft.com/resources/documentation/Windows/X
> P/all/reskit/en-us/Default.asp?
> url=/resources/documentation/windows/xp/all/reskit/en-
> us/prdp_log_fann.asp
>
> By default, all computers that are not-domain controllers
> will also receive the default domain account policy for
> their local accounts. However different account policies
> might be established for local accounts on computers that
> are not domain controllers by setting an account policy
> at the organizational unit level. Account policies for
> stand-alone computers can be set using Local Security
> Policy
> ----
Hi

Note the wording "local accounts" in the text above. This means
local users on each computer (e.g. the "Administrator" user) and
not AD domain user accounts.

-- 
torgeir, Microsoft MVP Scripting and WMI, Porsgrunn Norway
Administration scripting examples and an ONLINE version of
the 1328 page Scripting Guide:
http://www.microsoft.com/technet/scriptcenter/default.mspx


Relevant Pages

  • Re: Adding a Local User whose Password Violated Group Password Policy...
    ... Since there is no impact on passwords of machine local account that ... you are actually enforcing the account policies on OUs as well as in GPO ... > We have been using local accounts for IIS security. ...
    (microsoft.public.security)
  • Re: Domain-level group policies
    ... If users normally use domain accounts, ... Microsoft state that defining these policies is a ... passwords must be changed every 42 days, but I have a separate ... scope of those policies application (i.e. computers in the OU). ...
    (microsoft.public.windows.group_policy)
  • Re: Group Policy
    ... yes, a new password policies was added in a new OU for a group of computers, ... I set the policy setting to "DISABLED" for the policy named "Password must ... In a domain -- there can be only one password (account) policy and this one ...
    (microsoft.public.windows.server.security)
  • Re: Alerting - Malicious software removal tool
    ... >needed to install an application that she could not install from ... >"Administrator" account. ... You failed to analyze the root cause and correct it ... use their computers to have fun. ...
    (microsoft.public.security.virus)
  • RE: User template question
    ... Account tab). ... A new logon script was also assigned from the Profile tab. ... I'm afraid that your purpose cannot be achieved through User Template. ... Deploys software to user computers. ...
    (microsoft.public.windows.server.sbs)