Policy changes are not recognized

From: Ed Ireland (EdIreland_at_discussions.microsoft.com)
Date: 01/28/05


Date: Fri, 28 Jan 2005 09:23:04 -0800

Any help would be greatly appreciated!

I'm having trouble turning off a GP set at the Domain level.

The "Default Domain Security Policy" only addresses the "password policy"
settings under "Computer Configuration | Windows Settings | Security Settings
| Account Policies". This policy requires password renewal every 38 days, 0
days minimum duration, 8 character min length, etc., for users that are not a
member of a "Domain Static Authentication" security group that I created.

The "Default Domain Security Policy" is the second of two GP's at the Domain
level. The first policy, "Default Domain Policy" contains no settings
related to "password policy"

The policy worked well when first implemented, only affecting those not
contained in the Domain Static Auth group.

I configured this as detailed in MS KB article
http://support.microsoft.com/default.aspx?scid=kb;en-us;322176 under the
section: "How to Filter the Scope of Group Policy According to Security Group
Membership"

Opening Properties | Security on the Default Domain Security Policy shows
that the Security group Domain Static Authentication is allowed "READ" and
denied "Apply Group Policy".

Now, I need to turn off the policy, but am unable to do so. The users that
the policy was originally applied to are still being asked to renew their
password.

I have tried:
-adding the users that I do not want affected to the Domain Static Auth group

-disabling the Default Domain Security Policy

-checking for block inheritance settings (found none)

-deleting the Default Domain Security Policy (now recreated)

-running the secedit / refreshpolicy commands from the domain controller,
and the GPUDATE command from the XP client as referenced in
http://support.microsoft.com/default.aspx?scid=kb;en-us;887421

GPResult reports:
"Default Domain Security Policy"
Filtering: Denied (Security)

Please let me know what I have done wrong.

Thanks -- Ed



Relevant Pages

  • Re: Security Groups
    ... Access this computer from the network. ... You may also want to check security options in the same domain security policy and see if any restrictions exist? ... domain when they are in a security group. ...
    (microsoft.public.windows.server.sbs)
  • Remaining SIDs left behind after account deletion
    ... In the Domain Security Policy Settings I have some SIDs remaining that are ... from an account being deleted from the domain but I am not positive. ...
    (Focus-Microsoft)
  • Re: Password rotation
    ... thats what that article said as well. ... It will effect your security in that users could rapidly ... >> characters and an old one cannot be used again. ... >> This is the domain security policy ...
    (microsoft.public.win2000.security)
  • Re: XP machines lockout user accounts when security log is full.
    ... There is a security policy setting that is supposed to prevent that. ... it in Domain Security Policy or at the OU level. ... policies/security options - shut down system immediately in unable to audit security ...
    (microsoft.public.win2000.security)
  • Re: GPO Update Problem (SYSVOL access via UNC)
    ... Server Security and Auditing Policy ... This list only includes links in the domain of the GPO. ... The settings in this GPO can only apply to the following groups, users, ...
    (microsoft.public.win2000.group_policy)