Account Policy clarification

From: John (John_at_discussions.microsoft.com)
Date: 12/18/04


Date: Fri, 17 Dec 2004 17:31:08 -0800

I'm kind of confuse on the settings on the account policy. Running Win2K3
AD. Workstations are Win2K and XP, mostly. I set the account policy on the
Default Domain Security. Let say, I set the password history to 3, max pass
age to 20 day, min pass age to 1, and min pass length to 5. Then my lock out
policy is duration to 20, threshold to 5 attempts, and reset counter after 20
minutes.

My question is, since this affect the domain, would it also affect the local
account on my workstations THAT IS part of the domin. For example, I have a
Win2K workstation on the domain with two local user accounts. Those two
local user accounts are admin accounts. The "Password never expire" ARE NOT
check on their properties. Their passwords have not been changed in 90 days.
 Since this workstation is part of the domain above, when I log in locally to
this computer with the local account, would it force me to change my local
user's password?

basically, my question is would setting the account policy on the Default
Domain Policy affect the local users account, if the workstation is part of
the domain?



Relevant Pages

  • Re: Trust relationship between this workstation and Primary Domain
    ... it, with a new computer ID, a new workgroup ID, but again to no avail. ... password policy, renamed admin account, automatic updates are controlled by ... * PLEASE post all messages and replies in the newsgroups ... "Workstation ...
    (microsoft.public.win2000.networking)
  • Re: Re-Post - "the trust relationship between this workstation and
    ... account is NEW to the workstation. ... needs admin group priv at workstation level. ... only problem is adding a new user account on the station. ... This would be on the DNS server 172.20.100.2 ...
    (microsoft.public.windows.server.active_directory)
  • Re: Re-Post - "the trust relationship between this workstation and
    ... "the trust relationship between this workstation and the primary domain ... only problem is adding a new user account on the station. ... The DNS Zone for your AD Domain must be DYNAMIC, ... Client computer must use STRICTLY the INTERNAL DNS server which can ...
    (microsoft.public.windows.server.active_directory)
  • Joining NT4 to a Windows 2000 domain; secure channel prob?
    ... Trying to logon with a domain account pops up the error: ... The trust relationship between this workstation and the primary ... Searching PDC for domain MYDOMAIN ... ...
    (microsoft.public.windows.server.active_directory)
  • Re: Re-Post - "the trust relationship between this workstation and
    ... There were no logged events in either the DC or workstation. ... DC/DNS Server - DCDiag ... Attr: subschemaSubentry ... only problem is adding a new user account on the station. ...
    (microsoft.public.windows.server.active_directory)