Re: 2003 R2 and Group Policies



not laughing, but a few comments

"Dug Yodi" <dugyodi@xxxxxxxxx> wrote in message
news:1143665641.202841.96080@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Ok, nobody laugh at me... here's the deal.

1. You can only have one Password Account and Account Lockout Policy
per domain which is defined in the Default Domain Policy.
defined in a GPO linked to the domain (not necessarily the Default Domain
Policy)

2. Block Inheritence has no effect on these policies.
Actually it does, but not for domain accounts.
Consider, GPO 1 linked to OU 1, GPO 2 linked to OU 2 which OU is
a subOU within OU 1. Both GPO 1 and GPO 2 set values for Account
Policies. If OU 2 does not block policies, then the merge of Account
Policy settings from Domain, then GPO 1, and finally GPO 2 will apply
to the local SAM of any machines within OU 2. If OU 2 does block
policies, then only Account policies defined in GPO 2 are used in those
machines (unless upper GPOs has "enforced", aka "no override" set).


3. The local polices that were active when the server was promoted to
DC will be active if the Default Domain Policy is set to disabled.
4. When in double run "net accounts" from command prompt and it will
reveal the current policy settings that are active.

Clear as mud?



.



Relevant Pages

  • Re: Filter GPO by group
    ... It's true that the accounts policies only can be defined within athe GPO at ... account policy, if you need diffrent policies for diffrent users, write your ... > Technet recommends to not alter the default Domain policy, ...
    (microsoft.public.windows.server.active_directory)
  • Re: GPO causing client security logs to fill?
    ... a virus in play. ... settings to be applied on your client workstations. ... Group Policy is a complex and often misunderstood beast. ... I modified the account ...
    (microsoft.public.windows.server.sbs)
  • Re: Passowrd complexity LOCAL Account
    ... Place this computer account into an OU. ... Then, link a new GPO to the OU, ... configuring the GPO's Account Policy like you want the local SAM to behave. ... > local user accounts with passwords that do not follow the ...
    (microsoft.public.win2000.group_policy)
  • Re: Password policy, no override
    ... DCs will ignore any password policies you set at the domain controller ... I would disagree with setting the password policy on the Default ... > account and not the Domain user account object). ...
    (microsoft.public.win2000.active_directory)
  • Re: Cannot edit "Log on as a service" and "Allow log on locally" policies on W2K3 server.
    ... I am installing a new version of a program on my W2K3 SP1 server and one of the requirements is to create a "local" user account and grant this account ... However when I go into the Local Security Policy editor/Security settings/Local Policies/User Rights Assignment, I do not get the option to add or edit. ... These two policies both have different icons showing so I'm not sure what that indicates but am sure it has to do with why I cannot make any changes there. ... drill down to those settings and it'll tell you which policy is applying to those settings. ...
    (microsoft.public.windows.server.general)