Re: GPO Improvements with server 2008

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Howdie!

Bad Beagle wrote:
Can anyone give me some more information about the GPO improvements with server 2008? I would really like to use the new GPOs for domain password policies. Do i need to upgrade my domain to 2008 in order to use these features? Do I need to have Vista workstations?

there are a lot of papers out there stating the improvements of GPOs in Server 2008. One of the better ones is Jakob's line p at windowsecurity:
http://www.windowsecurity.com/articles/Group-Policy-related-changes-Windows-Server-2008-Part1.html

In order to use the Fine-grained password policies as they are called, you need to have Windows Server 2008 domain functional level which means that all DCs of the domain need to be 2008 (no pre 2008 DCs any more!). You don't need Vista for those fine-grained Password Policies - that'll work with "legacy" clients.

cheers,

Florian
--
Microsoft MVP - Group Policy
eMail: prename [at] frickelsoft [dot] net.
blog: http://www.frickelsoft.net/blog.
Maillist (german): http://frickelsoft.net/cms/index.php?page=mailingliste
.



Relevant Pages

  • Re: Security event after AD installation
    ... Check for all the Terminal Services GPOs that are currently applying to your DC and Domain. ... You're onto something here, I've just noticed that the event is only logged when I remote desktop into the server, I'm not sure how to correct this though - any pointers gratefully received. ... "Augusto Alvarez" wrote in message ...
    (microsoft.public.windows.server.setup)
  • Re: Reset password every three days
    ... Check the event logs for group policy errors on the SBS server. ... I haven't created any GPOs. ...
    (microsoft.public.windows.server.sbs)
  • Re: Using GPO to implement Password Policy
    ... you will need at least a separate server. ... Password, Kerberos, and Lockout policy. ... To use password policies you must use them at the domain level. ... I then attempted to then link this GPO to a test OU, ...
    (microsoft.public.windows.server.active_directory)
  • HELP! No GPO in effect, but restrictions still apply
    ... Windows 2003 Server, all critical updates applied ... I hadn't yet moved the workstation to an OU where I have the GPOs are ...
    (microsoft.public.win2000.group_policy)
  • Re: Reset password every three days
    ... Check the event logs for group policy errors on the SBS server. ... the RSOP afterwards to see if the max pwd time has infact been changed. ... I haven't created any GPOs. ...
    (microsoft.public.windows.server.sbs)