PC Review


Reply
Thread Tools Rate Thread

Account policy works only at domain level

 
 
Corrado
Guest
Posts: n/a
 
      8th Jun 2004
I've tried to create an account policy for limit password change limits but
it works only if the policy is created at domain level (where also Default
Domain Policy is present).
If I create the same policy at OU level, no setting is applied.

We have a w2000 domain in mixed mode with one NT4 BDC running.

Thanks
Corrado


 
Reply With Quote
 
 
 
 
Steven L Umbach
Guest
Posts: n/a
 
      8th Jun 2004
That is by design and one of the few settings that do not work like other GP
settings. For domain users, account policy can only be configured at the domain level
with no workarounds. If you configure at the OU level it will however be enforced on
local user accounts for computers in that OU. -- Steve



"Corrado" <(E-Mail Removed)> wrote in message
news:uH%(E-Mail Removed)...
> I've tried to create an account policy for limit password change limits but
> it works only if the policy is created at domain level (where also Default
> Domain Policy is present).
> If I create the same policy at OU level, no setting is applied.
>
> We have a w2000 domain in mixed mode with one NT4 BDC running.
>
> Thanks
> Corrado
>
>



 
Reply With Quote
 
Corrado
Guest
Posts: n/a
 
      8th Jun 2004
Thank you Steven,
so I can stop to make me crazy understanding this strange thing.

bye
Corrado


"Steven L Umbach" <(E-Mail Removed)> ha scritto nel messaggio
news:CPjxc.67949$Ly.62324@attbi_s01...
> That is by design and one of the few settings that do not work like other

GP
> settings. For domain users, account policy can only be configured at the

domain level
> with no workarounds. If you configure at the OU level it will however be

enforced on
> local user accounts for computers in that OU. -- Steve
>
>
>
> "Corrado" <(E-Mail Removed)> wrote in message
> news:uH%(E-Mail Removed)...
> > I've tried to create an account policy for limit password change limits

but
> > it works only if the policy is created at domain level (where also

Default
> > Domain Policy is present).
> > If I create the same policy at OU level, no setting is applied.
> >
> > We have a w2000 domain in mixed mode with one NT4 BDC running.
> >
> > Thanks
> > Corrado
> >
> >

>
>



 
Reply With Quote
 
G. Ettlin
Guest
Posts: n/a
 
      10th Jun 2004
How can i enforce on local user accounts for computers in that OU?

"Steven L Umbach" <(E-Mail Removed)> wrote in message
news:CPjxc.67949$Ly.62324@attbi_s01...
> That is by design and one of the few settings that do not work like other

GP
> settings. For domain users, account policy can only be configured at the

domain level
> with no workarounds. If you configure at the OU level it will however be

enforced on
> local user accounts for computers in that OU. -- Steve
>
>
>
> "Corrado" <(E-Mail Removed)> wrote in message
> news:uH%(E-Mail Removed)...
> > I've tried to create an account policy for limit password change limits

but
> > it works only if the policy is created at domain level (where also

Default
> > Domain Policy is present).
> > If I create the same policy at OU level, no setting is applied.
> >
> > We have a w2000 domain in mixed mode with one NT4 BDC running.
> >
> > Thanks
> > Corrado
> >
> >

>
>



 
Reply With Quote
 
Steven L Umbach
Guest
Posts: n/a
 
      10th Jun 2004
Create a GPO for that OU or modify an existing one to have the account policy you
want for local users that log onto the computers in that OU. Configure under computer
configuration/Windows settings/security settings/account policies. --- Steve


"G. Ettlin" <(E-Mail Removed)> wrote in message
news:%23LBT%(E-Mail Removed)...
> How can i enforce on local user accounts for computers in that OU?
>
> "Steven L Umbach" <(E-Mail Removed)> wrote in message
> news:CPjxc.67949$Ly.62324@attbi_s01...
> > That is by design and one of the few settings that do not work like other

> GP
> > settings. For domain users, account policy can only be configured at the

> domain level
> > with no workarounds. If you configure at the OU level it will however be

> enforced on
> > local user accounts for computers in that OU. -- Steve
> >
> >
> >
> > "Corrado" <(E-Mail Removed)> wrote in message
> > news:uH%(E-Mail Removed)...
> > > I've tried to create an account policy for limit password change limits

> but
> > > it works only if the policy is created at domain level (where also

> Default
> > > Domain Policy is present).
> > > If I create the same policy at OU level, no setting is applied.
> > >
> > > We have a w2000 domain in mixed mode with one NT4 BDC running.
> > >
> > > Thanks
> > > Corrado
> > >
> > >

> >
> >

>
>



 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Over Domain Level Password Age Policy Plsntn Rules Microsoft Windows 2000 Active Directory 1 15th Jul 2004 08:55 PM
Apply OU level policy OK, but domain level policy not applying to one OU =?Utf-8?B?cm9iYmlldHdpbHNvbg==?= Microsoft Windows 2000 Group Policy 0 5th Apr 2004 06:46 PM
Error when changing Account Lockout policy for default domain policy Jeanne Microsoft Windows 2000 Active Directory 2 18th Nov 2003 12:22 AM
Local Password Policy verus domain level policy Joe Microsoft Windows 2000 Group Policy 1 12th Sep 2003 06:56 PM
Local Password Policy verus domain level policy Joe Microsoft Windows 2000 1 12th Sep 2003 06:56 PM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 09:02 PM.