Re: Password requirement

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Ulf B. Simon-Weidner [MVP] (nospam2-ulf_at_usw-consulting.com)
Date: 08/29/04


Date: Sun, 29 Aug 2004 04:00:55 -0700


"Levi" <anonymous@discussions.microsoft.com> wrote in message
news:1ec201c48d25$37ead620$a501280a@phx.gbl:
> I get a message when trying to add a new user saying
> minimum password policy requirement requires a password of
> blah, blah.
>
> I have disabled the group policy, but still will not allow
> me to create a user.
>
> FYI my admin account does not have a password assigned, if
> that matters how can I change without reinstallation of
> the OS.
>
Hello Levi,

Account Policies (stuff like password requirements) for domain user
accounts is defined ONLY in the Default Domain Policy. All other
policies apply only to local useraccounts on the computer(accounts) to
whom the policy applies. If you want to change the policies make sure
that you keep them activated but change the values (e.g. set password
length to 0). Note that it's recommended that you have strong and long
passwords or passphrases.

I don't see why you should not be able to create useraccounts, just use
strong passwords. Passwords are not in place to annoy you, but to
secure your network. A regular password which does not meet the default
requirements is usually hacked within minutes (or even seconds).

The password of the administrator is unrelated to your issue, but it's
recommended that you set a strong password to prevent attackers. To
change the password, you can either log on with that account, press
Ctrl-Alt-Del and choose Change Password, or you'd be able to use the
"net user" command, or for a domain account you'd be able to start the
Active Directory-Users and -Computers managementconsole, navigate the
the useraccount and select to change the password from the contextmenu.
Or to change the password of a local account you can open the
Computermanagement managementconsole (e.g. right click on my computer
-> manage), navigate the the useraccounts and change the password using
the contextmenu of the user.

-- 
Gruesse - Sincerely,
Ulf B. Simon-Weidner


Relevant Pages

  • Re: Password policy, no override
    ... DCs will ignore any password policies you set at the domain controller ... I would disagree with setting the password policy on the Default ... > account and not the Domain user account object). ...
    (microsoft.public.win2000.active_directory)
  • Re: Cannot edit "Log on as a service" and "Allow log on locally" policies on W2K3 server.
    ... I am installing a new version of a program on my W2K3 SP1 server and one of the requirements is to create a "local" user account and grant this account ... However when I go into the Local Security Policy editor/Security settings/Local Policies/User Rights Assignment, I do not get the option to add or edit. ... These two policies both have different icons showing so I'm not sure what that indicates but am sure it has to do with why I cannot make any changes there. ... drill down to those settings and it'll tell you which policy is applying to those settings. ...
    (microsoft.public.windows.server.general)
  • Re: GPO configuration
    ... > account/password policy undefined and apply different OU ... > the domain level override OU level? ... I thought the lower GPO policies ... All domain controllers will get their Account ...
    (microsoft.public.cert.exam.mcse)
  • Re: Lock Account/Logoff Time-out
    ... the newer newsgroup for group policy is ... The policies you seem to be using is are not Account Policies ... these settings apply to network logins onto the server ...
    (microsoft.public.security)
  • Re: GPO causing client security logs to fill?
    ... a virus in play. ... settings to be applied on your client workstations. ... Group Policy is a complex and often misunderstood beast. ... I modified the account ...
    (microsoft.public.windows.server.sbs)