Re: password complexity

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: Marin Marinov (mlmarinov_at_askme.ca)
Date: 04/25/04


Date: Sun, 25 Apr 2004 09:17:58 -0400


<snip>
Ooook, now you really got me confused, Derek, and the "worst" part is
you're right ;) From my tests it appeared that the only Password policy
option available for change is Minimum password length and it's indeed
set to 7. And, of course, when I disable it in the domain-linked GPO the
local takes precedence. The question is: why? All other options are
disabled, plus I haven't seen a single document that didn't state that:
"For domain accounts, there can be only one account policy. The account
policy must be defined in the Default Domain policy and is enforced by
the domain controllers that make up the domain. A domain controller
always obtains the account policy from the Default Domain Policy Group
Policy object, even if there is a different account policy applied to
the organizational unit that contains the domain controller"

So, I'm extremely curious to know the reasoning behind this (and I'm
sure Microsoft have solid arguments). It's really interesting to test
the behaviour on several DCs (which reminds me to set up another VM ;)).
Please post if you have the chance to experiment with this, Derek.

-- 
Cheers,
   Marin Marinov
   MCT,MCSE 2003,MCSE:Security 2003
-
This posting is provided "AS IS" with no warranties, and confers no 
rights.


Relevant Pages

  • Re: password length
    ... there can be only one account policy. ... local account policies can be different from the domain account policy, ... as when you define an account policy specifically for the local accounts. ...
    (microsoft.public.windows.server.setup)
  • Re: IS this a true statement about block inheritance at Domain Con
    ... policies applied to them the same as workstations. ... > even though the account policy information is a computer policy and not a ... >> Only accounts within the domain controllers ou would not inherit. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Kerberos User Ticket Lifetime
    ... Account policy is a single instance thing on domain ... the tricky part is the Kerberos is part of Account Policy. ... > groups to the appropriate GPO so that they will get the right settings. ... >>>with the Maximum User Ticket Lifetime parm? ...
    (microsoft.public.security)
  • Re: IS this a true statement about block inheritance at Domain Con
    ... even though the account policy information is a computer policy and not a ... > Only accounts within the domain controllers ou would not inherit. ... > Paul Bergson MCT, MCSE, MCSA, CNE, CNA, CCA ... >> If you have your account policy setup in your default domain policy and ...
    (microsoft.public.windows.server.active_directory)
  • Re: Password policy situation
    ... As far as I have experienced, Account Policy settings in the highest ... Just link it back to the Domain Root and set your password policy in here. ...
    (microsoft.public.windows.group_policy)