Re: Security Policy for OU?

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: ptwilliams (ptw2001_at_hotmail.com)
Date: 11/08/04


Date: Mon, 8 Nov 2004 23:11:07 -0000

If you think about this, everything makes sense. When you logon using a
domain account the DC authenticates you - not the local SAM. Therefore
applying the policy at a level whereby the domain controllers are not within
scope will only apply that policy to the machines within scope -hence, the
new restrictions at the local SAM level.

What complicates things here, is that there's a 'special' aspect to this,
whereby the domain controllers 'pull' this info. from the domain only (as
they are the domain).

You may also wish to apply local restrictions to machines -so that any local
accounts cannot have silly or blank passwords (although there is a
workaround that will enable user accounts to not have any password even with
password restrictions in place).

Hope this helps,

(If management give you hassle, tell them you'll need a new domain and
therefore at least another two servers and services licenses - they'll soon
forget about how difficult it is to put a capital letter and a number in
their Pa55w0rd ;-)

-- 
Paul Williams
http://www.msresource.net
http://forums.msresource.net
"frankcvc" <frankcvc@discussions.microsoft.com> wrote in message 
news:C9AFC5AD-2EEE-4AF7-B742-C5199E86E8DE@microsoft.com...
Thanks for your response, Ulf. I guess, for an OU, it can only inherit the
domain's account policies. Although you may create a policy for an OU with
Account Policy configured, it wouldn't take any effect..
Would a domain policy be inherited by its child domain? Couldn't test it
since I am running a single domain forest.
Frank
"Ulf B. Simon-Weidner [MVP]" wrote:
> "frankcvc" <frankcvc@discussions.microsoft.com> wrote in message
> news:frankcvc@discussions.microsoft.com:
> > Can you set up the security GPO at OU level, such as account and 
> > password
> > policies? I created such a policy but it didn't work. If it doesn't 
> > work,
> > why
> > Microsoft still made the options available in GPO editor?
> > Is there are a way to block domain default security settings? Tried to 
> > but
> > it didn't work either.  Wish someone could confirm my testing result.
> >
> > Many thanks,
> >
>
> Hello Frank,
>
> The account policies for domain users only apply if they are in the
> default domain policy.
>
> Account policies in every other policy only apply to local useraccount
> for the machine on whose the policy applies. E.g. the default domain
> controller policy only applies for the local sam, that means the local
> administrator account which is used to access the directory restore
> mode.
>
> -- 
> Gruesse - Sincerely,
>
> Ulf B. Simon-Weidner
>
>   MVP-Book "Windows XP - Die Expertentipps":  http://tinyurl.com/44zcz
>   Weblog: http://msmvps.org/UlfBSimonWeidner
>   WebSite: http://www.windowsserverfaq.org
> 


Relevant Pages

  • Re: GPO causing client security logs to fill?
    ... a virus in play. ... settings to be applied on your client workstations. ... Group Policy is a complex and often misunderstood beast. ... I modified the account ...
    (microsoft.public.windows.server.sbs)
  • Re: The local policy of this system does not permit you to logon i
    ... Security policies were propagated with warning. ... Error 0x534 occurs when a user account in one or more Group Policy objects ... I have checked the security policies & the administrator profile is not ...
    (microsoft.public.windows.server.sbs)
  • Re: GPO causing client security logs to fill?
    ... Unlink the Default Domain Controller Policy (As it was not previously ... settings to be applied on your client workstations. ... I modified the account ... So basically, the Account lockout threshold, account lockout ...
    (microsoft.public.windows.server.sbs)
  • Re: GPO causing client security logs to fill?
    ... Possibly delete the Default Domoan Controller Policy (As it did not ... issues as it was about recoverying from a virus which appears to ... with client logon failures. ... I modified the account ...
    (microsoft.public.windows.server.sbs)
  • Re: Domain Admin account and lockout Policy
    ... have different account policies for different domain user accounts, ... Topics, Group Policy Management, Concepts, Group Policy Object Editor ... Default Domain Policy Group Policy object (GPO) or in a new GPO that ...
    (microsoft.public.windows.group_policy)