2003 GP/Password complexity questions



I have a new 2003 AD domain and am looking for some guidance with the
following:

1. In regard to password complexity being enabled by default, I've
poked around the newsgroups/docs and understand how to turn this off
but haven't actually done it and don't fully understand the
requirements. I've seen it stated that you must set the password
policy options to disable this in the "Default Domain Policy" and I've
also seen it stated that this merely needs to be done "at the domain
level" which leads me to think that you could create another GPO at the
domain level that will effectively loosen password complexity
restrictions w/o having to modify the Defualt...

Can someone tell me which is the case? if so, are there advantages to
doing it one way or the other?

2. I have a fairly small network and will only need to use a basic set
of GPO's to accomplish what I need. Namely, I will mainly be using GP
for account policies, audit policies, security settings, and maybe
software installation. I'm trying to decide the best strategy for
dividing up the policies...i.e. should I use one policy for
workstations and one for servers (since I do want to manage them
differently), each with the aforementioned settings? or would it be
best to use separate GPO's for both. In other words, is there a good
reason to have separate GPO's for separate functions...so for servers
I'd have an account policy object, an audit policy object, and do the
same for workstations (in this case 4 total)?

Sorry for the long post...thanks to anyone willing to give me some
guidance or ideas!

.



Relevant Pages

  • Re: What Happened? Passwords all expired...
    ... really explain how the new account policy settingmade it to the DCs. ... I would strongly suggest enabling Success/Failure for Account Management ... >>>post that says "I check my GPO's and password complexity ... >>>>account logon events success and fail ...
    (microsoft.public.win2000.active_directory)
  • Re: GPO - password policy - Urgent
    ... Set password complexity to "disabled" - NOT undefined in Domain ... You can also use the mmc snapin for Resultant Set of Policy [again ... assuming Windows 2003] in logging mode on the domain controller to see what ... problems being that domain controllers are not pointing only to themselves ...
    (microsoft.public.windows.server.security)
  • Re: password complexity
    ... Marin and Dave, ... Here is what is happening when you remove the domain policy - account policy ... the domain policy for password complexity is removed from the DCs ...
    (microsoft.public.windows.server.active_directory)
  • Re: User Creation
    ... Didn't catch which version of Windows Active Directory you were running? ... > trivial matter of creating user accounts made me so ... >>W2k3 by default has password complexity enabled in Default ... >>password doesnot meet the password policy requirements. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Security hierarchy
    ... >would only apply to local machine accounts if domain policy is overridden.. ... that password complexity should not be enforced although it ... Local setting show ... >> I reboot the DC. ...
    (microsoft.public.win2000.security)