PC Review


Reply
Thread Tools Rate Thread

Block inheritance for Account Policy

 
 
Gary
Guest
Posts: n/a
 
      11th Jul 2004
Hello,

I'm planning to implement account policy at our
organization. As far as I understand account policy gpo to
work it should be linked to domain.
I have couple OUs containing system computer ans user
accounts and I do not want to apply account policy to
theses containers. The question is if I can block
inheritance of account policy for these specific
containers? Are there any special rules when applying
account policy?

I will be very grateful for your help,
Thanks,
Gary

 
Reply With Quote
 
 
 
 
Steven L Umbach
Guest
Posts: n/a
 
      11th Jul 2004
Account policy for "domain" users can only be configured at the domain level. If
configured at any other level, it will be ignored for domain users but apply to local
user accounts on domain computers in the OU where it is configured. -- Steve

"Gary" <(E-Mail Removed)> wrote in message
news:2aa2701c4672e$4a8715e0$(E-Mail Removed)...
> Hello,
>
> I'm planning to implement account policy at our
> organization. As far as I understand account policy gpo to
> work it should be linked to domain.
> I have couple OUs containing system computer ans user
> accounts and I do not want to apply account policy to
> theses containers. The question is if I can block
> inheritance of account policy for these specific
> containers? Are there any special rules when applying
> account policy?
>
> I will be very grateful for your help,
> Thanks,
> Gary
>



 
Reply With Quote
 
Mark Renoden [MSFT]
Guest
Posts: n/a
 
      11th Jul 2004
Hi Gary

Generally speaking, don't try to block domain wide account policy on special
accounts (service accounts etc) but rather use the options in the properties
of account itself such as "Password never expires". You then manually
change these passwords from time to time (something sensible) to reduce
successful attack likelihood.

Kind regards
--
Mark Renoden [MSFT]
Windows Platform Support Team
Email: (E-Mail Removed)

Please note you'll need to strip ".online" from my email address to email
me; I'll post a response back to the group.

This posting is provided "AS IS" with no warranties, and confers no rights.

"Steven L Umbach" <(E-Mail Removed)> wrote in message
news:WpeIc.52497$JR4.11876@attbi_s54...
> Account policy for "domain" users can only be configured at the domain
> level. If
> configured at any other level, it will be ignored for domain users but
> apply to local
> user accounts on domain computers in the OU where it is configured. --
> Steve
>
> "Gary" <(E-Mail Removed)> wrote in message
> news:2aa2701c4672e$4a8715e0$(E-Mail Removed)...
>> Hello,
>>
>> I'm planning to implement account policy at our
>> organization. As far as I understand account policy gpo to
>> work it should be linked to domain.
>> I have couple OUs containing system computer ans user
>> accounts and I do not want to apply account policy to
>> theses containers. The question is if I can block
>> inheritance of account policy for these specific
>> containers? Are there any special rules when applying
>> account policy?
>>
>> I will be very grateful for your help,
>> Thanks,
>> Gary
>>

>
>



 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Block policy inheritance not working Wires Microsoft Windows 2000 Active Directory 0 17th Jul 2006 07:40 PM
Block Policy Inheritance not working Wires Microsoft Windows 2000 0 14th Jul 2006 04:00 PM
Block Policy Inheritance Dan Microsoft Windows 2000 Active Directory 2 16th Jan 2006 03:10 PM
Block Policy Inheritance does not work Brian Nielsen Microsoft Windows 2000 Group Policy 6 11th May 2005 06:16 PM
Default Domain Policy and Block Policy Inheritance Anwar Mahmood Microsoft Windows 2000 Group Policy 1 30th Jun 2003 08:32 PM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 07:11 AM.