Re: Different Password Policy for Domain versus sub-Domain

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



C Emmons wrote:
We are preparing to setup password policies for our domain -- however, we do not want it to apply to the users in the sub-domain. We are a university and have the staff/faculty and student accounts divided. We have Windows 2003 SP1. Is there any way to do this? I see posts indicating that the policy in applied at the domain level. I did see a comment about setting the 'passwords do not expire'. If a script were written to set accounts to 'passwords do not expire' would this override the group policy at the domain level. Can anyone direct me a link on using group policy to setup password policies. Thanks for any help.

If You are thinking about sub-domain as a child domain in the same forest then it is exactly as You requires it to be - child domain will have its own password policy.

Password never expires is not forced at GPO level and this is per account setting so yes, this will override password requirements if it comes to change password but not if it comes to complexity etc.

--
Tomasz Onyszko
http://www.w2k.pl/ - (PL)
http://blogs.dirteam.com/blogs/tomek/ - (EN)
.



Relevant Pages

  • Re: Group Policys and Passwords
    ... Password policy can only be set on domain level. ... > 2) Passwords expire yearly ... > group policy that is not effected by the top level policy? ...
    (microsoft.public.windows.server.general)
  • Re: Administrator restricted - Control Panel Missing
    ... If you did not specifically set up Group Policy to restrict access to ... The command net users will display user accounts and net user username will ... type of administrator. ... the control panel was missing. ...
    (microsoft.public.windowsxp.security_admin)
  • RE: Deny Log on Locally to some accounts through GPO
    ... Microsoft Windows Operating System Group Policy Result tool v2.0 ... Disable RDP Application Accounts ... Filtering: Not Applied ... This list only includes links in the domain of the GPO. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Deny Log on Locally to some accounts through GPO
    ... accounts reside... ... We also created a GPO named "Disable RDP Application Accounts". ... Microsoft Windows XP Operating System Group Policy Result tool ... Filtering: Not Applied ...
    (microsoft.public.windows.server.active_directory)
  • Re: debugger user autochange
    ... One possibility could be that Group Policy Restricted Groups are being ... applied to the computers in question. ... I think I failed to convey the problem clearly - the user accounts ... domain/userxyz assigned to the administrator group. ...
    (microsoft.public.windowsxp.security_admin)