PC Review


Reply
Thread Tools Rate Thread

cannot change account policies

 
 
Jacky Ho
Guest
Posts: n/a
 
      11th Aug 2003
I've a default domain controller group policy.
This is policy is applied to DC.
However, I found the account policies setting in windows settings in
computer configuration cannot update to the DC
after I change those settings in the default domain controller group policy.
I try to change the max. size of application log and then use command
"secedit /refreshpolicy machine_policy /enforce".
The changes on the application log is updated.
And I use gpresult and found the DC is now only applied this group policy
only on security settings.

The following are the details of the group policy and effective settings :

Default DC policy
Effective settings
Password Policy :
Enforce password history : 24
24
Max. password age: 70 days
70 days
Min. password age: 2 days
2 days
Min. password length : 8
8
Passwords must meet complexity : Enabled Enabled
Account Lockout Policy :
Account lockout duration : Not defined 0
Account lockout threshold: 0 invalid 3
invalid
Reset account lockout counter after Not defined 90 minutes
Kerberos Policy :
Enforce user logon restrictions : Not defined
Disabled
Max . lifetime for service ticket : Not defined
600 mins.
Max. lifetime for user ticket : Not defined
10 hours
Max. lifetime for user ticket : Not defined
7 days
Max. tolerance for computer clock synchronization : Not defined
5 mins.

I also try to change all settings in account lockout policy to some values,
not " not defined".
and then secedit to update the policy but still the effective settings not
change.

Please Help.

Jacky


 
Reply With Quote
 
 
 
 
Curtis Clay III [MSFT]
Guest
Posts: n/a
 
      11th Aug 2003
You will need to change you password and any other security policy at the
Domain level not the Domain controller level. Security policy only applies
at the domain level.
"Jacky Ho" <(E-Mail Removed)> wrote in message
news:%(E-Mail Removed)...
> I've a default domain controller group policy.
> This is policy is applied to DC.
> However, I found the account policies setting in windows settings in
> computer configuration cannot update to the DC
> after I change those settings in the default domain controller group

policy.
> I try to change the max. size of application log and then use command
> "secedit /refreshpolicy machine_policy /enforce".
> The changes on the application log is updated.
> And I use gpresult and found the DC is now only applied this group policy
> only on security settings.
>
> The following are the details of the group policy and effective settings :
>
> Default DC policy
> Effective settings
> Password Policy :
> Enforce password history : 24
> 24
> Max. password age: 70 days
> 70 days
> Min. password age: 2 days
> 2 days
> Min. password length : 8
> 8
> Passwords must meet complexity : Enabled Enabled
> Account Lockout Policy :
> Account lockout duration : Not defined 0
> Account lockout threshold: 0 invalid

3
> invalid
> Reset account lockout counter after Not defined 90

minutes
> Kerberos Policy :
> Enforce user logon restrictions : Not defined
> Disabled
> Max . lifetime for service ticket : Not defined
> 600 mins.
> Max. lifetime for user ticket : Not defined
> 10 hours
> Max. lifetime for user ticket : Not defined
> 7 days
> Max. tolerance for computer clock synchronization : Not defined
> 5 mins.
>
> I also try to change all settings in account lockout policy to some

values,
> not " not defined".
> and then secedit to update the policy but still the effective settings not
> change.
>
> Please Help.
>
> Jacky
>
>



 
Reply With Quote
 
Jacky Ho
Guest
Posts: n/a
 
      11th Aug 2003
Thanks !
I can update the account lockout policy now.
Any othe policies are also only apply when make changes to specific policy ?

Jacky

"Curtis Clay III [MSFT]" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed)...
> You will need to change you password and any other security policy at the
> Domain level not the Domain controller level. Security policy only applies
> at the domain level.
> "Jacky Ho" <(E-Mail Removed)> wrote in message
> news:%(E-Mail Removed)...
> > I've a default domain controller group policy.
> > This is policy is applied to DC.
> > However, I found the account policies setting in windows settings in
> > computer configuration cannot update to the DC
> > after I change those settings in the default domain controller group

> policy.
> > I try to change the max. size of application log and then use command
> > "secedit /refreshpolicy machine_policy /enforce".
> > The changes on the application log is updated.
> > And I use gpresult and found the DC is now only applied this group

policy
> > only on security settings.
> >
> > The following are the details of the group policy and effective settings

:
> >
> > Default DC policy
> > Effective settings
> > Password Policy :
> > Enforce password history : 24
> > 24
> > Max. password age: 70 days
> > 70 days
> > Min. password age: 2 days
> > 2 days
> > Min. password length : 8
> > 8
> > Passwords must meet complexity : Enabled

Enabled
> > Account Lockout Policy :
> > Account lockout duration : Not defined

0
> > Account lockout threshold: 0 invalid

> 3
> > invalid
> > Reset account lockout counter after Not defined 90

> minutes
> > Kerberos Policy :
> > Enforce user logon restrictions : Not defined
> > Disabled
> > Max . lifetime for service ticket : Not defined
> > 600 mins.
> > Max. lifetime for user ticket : Not defined
> > 10 hours
> > Max. lifetime for user ticket : Not defined
> > 7 days
> > Max. tolerance for computer clock synchronization : Not defined
> > 5 mins.
> >
> > I also try to change all settings in account lockout policy to some

> values,
> > not " not defined".
> > and then secedit to update the policy but still the effective settings

not
> > change.
> >
> > Please Help.
> >
> > Jacky
> >
> >

>
>



 
Reply With Quote
 
Eric Burke [MSFT]
Guest
Posts: n/a
 
      12th Aug 2003
Hi Jacky,

Specifically, only account policies apply at the domain level. By default
those are configured in the Default Domain Policy. All other policies should
be configurable from any container location.

--
Eric Burke [MSFT]
Microsoft Directory Services
--

This posting is provided "AS IS" with no warranties, and confers no rights.
Use of included script samples are subject to the terms specified at
http://www.microsoft.com/info/cpyright.htm

Note: For the benefit of the community-at-large, all responses to this
message are best directed to the newsgroup/thread from which they
originated.
"Jacky Ho" <(E-Mail Removed)> wrote in message
news:eF$(E-Mail Removed)...
> Thanks !
> I can update the account lockout policy now.
> Any othe policies are also only apply when make changes to specific policy

?
>
> Jacky
>
> "Curtis Clay III [MSFT]" <(E-Mail Removed)> wrote in message
> news:(E-Mail Removed)...
> > You will need to change you password and any other security policy at

the
> > Domain level not the Domain controller level. Security policy only

applies
> > at the domain level.
> > "Jacky Ho" <(E-Mail Removed)> wrote in message
> > news:%(E-Mail Removed)...
> > > I've a default domain controller group policy.
> > > This is policy is applied to DC.
> > > However, I found the account policies setting in windows settings in
> > > computer configuration cannot update to the DC
> > > after I change those settings in the default domain controller group

> > policy.
> > > I try to change the max. size of application log and then use command
> > > "secedit /refreshpolicy machine_policy /enforce".
> > > The changes on the application log is updated.
> > > And I use gpresult and found the DC is now only applied this group

> policy
> > > only on security settings.
> > >
> > > The following are the details of the group policy and effective

settings
> :
> > >
> > > Default DC policy
> > > Effective settings
> > > Password Policy :
> > > Enforce password history : 24
> > > 24
> > > Max. password age: 70 days
> > > 70 days
> > > Min. password age: 2 days
> > > 2 days
> > > Min. password length : 8
> > > 8
> > > Passwords must meet complexity : Enabled

> Enabled
> > > Account Lockout Policy :
> > > Account lockout duration : Not defined

> 0
> > > Account lockout threshold: 0 invalid

> > 3
> > > invalid
> > > Reset account lockout counter after Not defined 90

> > minutes
> > > Kerberos Policy :
> > > Enforce user logon restrictions : Not defined
> > > Disabled
> > > Max . lifetime for service ticket : Not defined
> > > 600 mins.
> > > Max. lifetime for user ticket : Not defined
> > > 10 hours
> > > Max. lifetime for user ticket : Not defined
> > > 7 days
> > > Max. tolerance for computer clock synchronization : Not defined
> > > 5 mins.
> > >
> > > I also try to change all settings in account lockout policy to some

> > values,
> > > not " not defined".
> > > and then secedit to update the policy but still the effective settings

> not
> > > change.
> > >
> > > Please Help.
> > >
> > > Jacky
> > >
> > >

> >
> >

>
>



 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Administrator on Vista computer cannot change account policies. =?Utf-8?B?TWljcm9zb2Z0bG92ZXI=?= Windows Vista Security 5 26th Nov 2007 06:39 PM
Account Policies - NT Carlos Felipe França da Fonseca Microsoft Windows 2000 Group Policy 0 19th Jan 2006 08:14 PM
Account Policies HelpPls Microsoft Windows 2000 Active Directory 3 20th Apr 2004 02:21 PM
Account Policies Mike Microsoft Windows 2000 Active Directory 2 26th Nov 2003 10:23 PM
Account Policies nathan Microsoft Windows 2000 Group Policy 1 20th Oct 2003 02:03 AM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 11:52 PM.