Re: Group Policy Question

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Yes you did. I was hoping I misunderstood... I'm all set as I am. Thanks
for taking the time to answer!

Another question for you... When a user changes there password and gets
locked out is there any easy way to find out from what means or machine is
the culprit?

Thanks in advance!

"Cary Shultz" wrote:

> Stosti,
>
> Didn't I just explain this?
>
> --
> Cary W. Shultz
> Roanoke, VA 24012
> "stosti" <stosti@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
> news:23C6EE00-34CB-409B-A8D8-3EEEBA16FBF7@xxxxxxxxxxxxxxxx
> > Thank You!
> >
> > OK... If I remove the password policy from the top level can I put a
> > password policy on each OU?
> >
> > Regards,
> > Scott
> >
> > "Jorge de Almeida Pinto [MVP]" wrote:
> >
> >> Use the GPMC
> >> (http://www.microsoft.com/windowsserver2003/gpmc/default.mspx
> >> and
> >> http://www.microsoft.com/downloads/details.aspx?FamilyID=0A6D4C24-8CBD-4B35-9272-DD3CBFC81887&displaylang=en),
> >> create additional GPOs and link the GPOs to the OUs you created.
> >>
> >> It is not possible to configure password policies on an OU for users in a
> >> domain.
> >>
> >> The correct answer for this is:
> >> Password policies can only be configured at REALM level for the users
> >> within
> >> that REALM.
> >>
> >> What is a REALM? A realm could be a domain, a single server, a single
> >> client.
> >> For all mentioned, users can be created in the realm. For the domain you
> >> can
> >> create domain users and for single servers and clients you can create
> >> local
> >> users that belong only to the local server or client
> >>
> >> If you apply password policies at domain level the policies apply to
> >> domain
> >> users and local users on each server and client
> >> If you apply password policies at OU level the policies apply ONLY to the
> >> users of the servers or clients within that OU
> >>
> >> So if you want different password policies you need multiple domains OR
> >> you
> >> could use third party products that provides this functionality
> >>
> >> --
> >>
> >> Cheers,
> >> (HOPEFULLY THIS INFORMATION HELPS YOU!)
> >> # Jorge de Almeida Pinto #
> >> MVP Windows Server - Directory Services
> >> BLOG --> http://blogs.dirteam.com/blogs/jorge/default.aspx
> >> -----------------------------------------------------------------------------
> >> * This posting is provided "AS IS" with no warranties and confers no
> >> rights!
> >> * Always test before implementing!
> >> -----------------------------------------------------------------------------
> >>
> >>
> >> -----------------------------------------------------------------------------
> >> "stosti" <stosti@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
> >> news:C5B0F3B7-20A8-4F01-A57B-4B5881672B6A@xxxxxxxxxxxxxxxx
> >> > Today I have a default group policy for all of my users. I created a
> >> > different O.U. for each department. Now I would like a different group
> >> > policy per O.U. Do you have instructions for doing this?
> >> >
> >> > Example I will set a different password policy per OU.
> >> >
> >> > Thanks,
> >> > Scott
> >>
> >>
> >>
>
>
>
.



Relevant Pages

  • Re: Cross realm authentication
    ... that should include all kerberos ... Can you provide more information about the client that does the cross ... Realm: realm1.com ... I have added 2 way trust in realm1 Active Directory Domains and trusts of windows 2003 server. ...
    (comp.protocols.kerberos)
  • Re: Event ID 4
    ... Server Time: ... Client Realm: ... that server is not capable of authenticating with Kerberos. ...
    (microsoft.public.win2000.security)
  • Re: Group Policy Question
    ... Password policies can only be configured at REALM level for the users within ... A realm could be a domain, a single server, a single ... users that belong only to the local server or client ...
    (microsoft.public.windows.server.active_directory)
  • Re: Cross realm authentication
    ... Please find the attached capture for cross realm setup. ... TGS-REQ going from client, please shed some light on the same. ... Server Name: krbtgt/realm2.com ...
    (comp.protocols.kerberos)
  • Re: Group Policy Question
    ... MVP Windows Server - Directory Services ... >> It is not possible to configure password policies on an OU for users in a ... >> Password policies can only be configured at REALM level for the users ... >> users that belong only to the local server or client ...
    (microsoft.public.windows.server.active_directory)