Re: Account Lockout Threshold change - Not taking effect



"sekhar" <sekhar@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message news:EE341FDE-2DEC-474D-8178-6C6FA2F21C20@xxxxxxxxxxxxxxxx

Hi Sekhar,

Maybe I may not be understanding what you are saying. Are you saying the GPO with the 5 attempts setting is not linked at the domain level, but rather it is liniked on an OU somewhere, such as where the Users OU is?

If it is on an OU, the password setting does not work. It only works if linked at the domain level, no where else. If it is 2008, there is a provision to make it work, but not with 2003 or older.

Ace





Hi Ace,

The other policy is linked at the domain level. It is at the lower OU level.
I even changed the settings to 5 attempt. But still it locks at 3 attempts.
Not sure from where it pulls the count of 3.

"Ace Fekay [MCT]" wrote:

"sekhar" <sekhar@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:3688E5DD-FC3A-46BF-928C-B1498ED8978E@xxxxxxxxxxxxxxxx
> Hi,
>
> Yes, we tested. The account gets locked at 3 attempts, and not 5. The
> correct default domin policy is getting applied, and it shows 5 > attempts.
> But
> still no luck....


Have you tried unlinking the additional GPO you've created at the Domain
level, and making sure the Default Domain Policy is set to 5 attempts, and
try again? If that works, that tells you it is pulling it from the default
domain. If you want to create an additional GPO with password control, you
will have to remove the settings in the Default Domain Policy and not change
the order of the GPOs at the domain level, since we would want thecdefault
GPO to run first.

If that doesn't work, then there is something else going on, such as
possible AD-client communications issues. I am assuming that none of the
machines (DC and clients) are using an external DNS server (such as the
ISP), and the DC is not multihomed (more than one NIC and/or IP address).

--
Ace

This posting is provided "AS-IS" with no warranties or guarantees and
confers no rights.

Please reply back to the newsgroup or forum for collaboration benefit among
responding engineers, and to help others benefit from your resolution.

Ace Fekay, MCT, MCTS Exchange, MCSE, MCSA 2003 & 2000, MCSA Messaging
Microsoft Certified Trainer

For urgent issues, please contact Microsoft PSS directly. Please check
http://support.microsoft.com for regional support phone numbers.





.



Relevant Pages

  • Re: Account Lockout Threshold change - Not taking effect
    ... So you are saying there is a GPO at the OU level with password settings. ... Just to reiterate, as Florian said, and as I mentioned in my previous post, password settings anywhere other than at the domain level on 2000 and 2003 do not work. ... The GPO (Default Domain Policy) that has the account lockout setting of 5 is ...
    (microsoft.public.windows.server.active_directory)
  • Re: New to Active Directory - we need help configuring GPO
    ... setting at the domain level would affect ALL objects domain wide, ... involve numerous GPO filtering for the objects ... If you don't want your admins ... Password settings and password policies will ONLY work at the Domain ...
    (microsoft.public.win2000.active_directory)
  • Re: Account Lockout Threshold change - Not taking effect
    ... The GPO (Default Domain Policy) that has the account lockout setting of 5 is ... Are you saying the GPO ... linked at the domain level, ...
    (microsoft.public.windows.server.active_directory)
  • Re: Multi site group policy - best practices question.
    ... In general it makes sense to configure a GPO at the domain level that you ... GPO with common settings that I wanted applied to all domain users and use ... > specific "users" group policy requirements that the other sites do not. ...
    (microsoft.public.windows.group_policy)
  • Re: How do you overide screensave setting in GP?
    ... the policy is not affecting. ... If the policy is at the domain leve meaning you set it in the Default Domain ... GPO and only apply it to either users or computers. ... saver setting is set at the domain level, you do not want to do that or you ...
    (microsoft.public.win2000.active_directory)

Loading