Re: Domain Password Policy



Thanks so much, that is what I needed. Yeah, the pc is in a locked room that
acts as an application server. So I guess it is kind of a server, but just
has XP Pro instead of the server software.

I thought the domain policy would override the tick that never expires.
This is good to know so we can create one service account where the password
never expires. Thanks so much for all the help.

This is truly what I wanted to know. Because from what I have heard you cant
set a password policy at the ou level it always had to be the domain level
and I was afraid that the few programs we use to run through windows
scheduler would quit working with the one service account that we use.

So basically set an domain security policy with one account for services and
click do not expire and this truly wont expire with the domain policy.

Thanks so much 1 problem down 1 to go,
Dan



"Lanwench [MVP - Exchange]" wrote:



In news:37B32174-612F-4568-96FC-E822ECECB5F1@xxxxxxxxxxxxx,
Dan <Dan@xxxxxxxxxxxxxxxxxxxxxxxxx> typed:
Hello and thanks for your quick response.
I agree we pretty much have one pc that acts as an application server
that handles the scripts. It does require both local pc admin access
and some rights to the server.

No way to stick that on a real server that isn't accessible to users? Eh,
what are you going to do.

So if I understand correctly we can set an account for this pc which
will not be affected by the domain security policy. How would this
work? Don't all accounts get affected by the domain policy.

Yes, but in the account properties in ADUC you can tick the box that
prevents the password from ever expiring.

I
greatly appreciate your help.

HTH.

Thanks
Dan


"Lanwench [MVP - Exchange]" wrote:



In news:746B1C59-4516-46F1-A490-A86AEDD8E02D@xxxxxxxxxxxxx,
Dan <Dan@xxxxxxxxxxxxxxxxxxxxxxxxx> typed:
Hello Everyone,
I am getting ready to enforce stronger passwords on the domain.
However, we have a lot of automatic scripts/jobs that run depending
on the machine. For instance on my pc I have an access database that
loads and runs through the windows scheduler. However, if my
password changes which it does the program quits running. Is there
away I can prevent this so I can ensure all of our jobs/scripts will
continue to run even if a password is expired or changed due to the
domain password policy.
Thanks
Dan

You can set up separate service accounts, with passwords that don't
expire, if you need to. That said, I'd say that it's best to avoid
running anything like this from your desktops. It would be better to
get everything centralized on your servers.



.



Relevant Pages

  • Re: RWW and Remote desktop stopped working on all clients
    ... After diggin through ALL the group policies, I found Remote ... Desktop DISABLED under the Account Lockout policy - I don't think I've even ... adminsitrator or another account with Domain Admin role; also the server ...
    (microsoft.public.windows.server.sbs)
  • Re: Terminal Server logon problem
    ... I upgraded our current SBS 2003 box to new hardware using SBSMigration.com's ... When it was time to bring the old SBS server offiline and make ... I am getting a group policy error - You do not have permissions to ... The only thing I thought I changed was taking the administrators account ...
    (microsoft.public.windows.server.general)
  • Re: Restrict to 1 program
    ... I would *not* apply the policy to the whole domain. ... Terminal Server computer account in this OU and link the policy to ... Configuration settings from the GPO linked to OU where the computer ...
    (microsoft.public.windows.terminal_services)
  • Re: Terminal Server logon problem
    ... You had a server that was upgraded to SBS 2003? ... I am getting a group policy error - You do not have permissions to perform ... The only thing I thought I changed was taking the administrators account out ... make the user a member of the Remote Desktop ...
    (microsoft.public.windows.server.general)
  • account lockout issues...
    ... I have a couple of question regarding the account lockout policy. ... I had originally set a local policy on our Win2K terminal server such ...
    (microsoft.public.backoffice.smallbiz2000)

Quantcast