PC Review


Reply
Thread Tools Rate Thread

Disabling the Default Domain Policy

 
 
Josh
Guest
Posts: n/a
 
      7th Jul 2004
All,

Does anyone know what the effects are of disabling the
default domain policy at the domain level?

Thanks.
 
Reply With Quote
 
 
 
 
Mark Renoden [MSFT]
Guest
Posts: n/a
 
      7th Jul 2004
Hi Josh

Effect is that Domain wide policy doesn't apply. It's not a good thing to
do. Why the question?

Kind regards
--
Mark Renoden [MSFT]
Windows Platform Support Team
Email: (E-Mail Removed)

Please note you'll need to strip ".online" from my email address to email
me; I'll post a response back to the group.

This posting is provided "AS IS" with no warranties, and confers no rights.

"Josh" <(E-Mail Removed)> wrote in message
news:27f0f01c4645c$16bc3b20$(E-Mail Removed)...
> All,
>
> Does anyone know what the effects are of disabling the
> default domain policy at the domain level?
>
> Thanks.



 
Reply With Quote
 
Darren Mar-Elia
Guest
Posts: n/a
 
      8th Jul 2004
Josh-
That's assuming of course, that there isn't another GPO linked to the
domain. I've had this conversation with some other folks before and there is
this "fear" that there is something magical about the Def. Domain Policy and
Def. DC Policy and that disabling them is bad. I haven't found that to be
the case. You just need to be aware of what the effects are, as Mark
indicates. If you set account policy, for example, through the Default
Domain Policy, and then you disable the DDP, that account policy won't be
undone--it just won't be change-able until you have another domain-linked
GPO available.

--
Darren Mar-Elia
MS-MVP-Windows Management
http://www.gpoguy.com



"Mark Renoden [MSFT]" <(E-Mail Removed)> wrote in message
news:Obh%(E-Mail Removed)...
> Hi Josh
>
> Effect is that Domain wide policy doesn't apply. It's not a good thing to
> do. Why the question?
>
> Kind regards
> --
> Mark Renoden [MSFT]
> Windows Platform Support Team
> Email: (E-Mail Removed)
>
> Please note you'll need to strip ".online" from my email address to email
> me; I'll post a response back to the group.
>
> This posting is provided "AS IS" with no warranties, and confers no

rights.
>
> "Josh" <(E-Mail Removed)> wrote in message
> news:27f0f01c4645c$16bc3b20$(E-Mail Removed)...
> > All,
> >
> > Does anyone know what the effects are of disabling the
> > default domain policy at the domain level?
> >
> > Thanks.

>
>



 
Reply With Quote
 
Josh
Guest
Posts: n/a
 
      8th Jul 2004
Well the reason I asked is because I have a domain were
the default domain policy is disabled and no policy is
linked to the domain. But there are still account lockout
after a certain amount of bad tries. Where is this policy
coming from?
>-----Original Message-----
>Josh-
>That's assuming of course, that there isn't another GPO

linked to the
>domain. I've had this conversation with some other folks

before and there is
>this "fear" that there is something magical about the

Def. Domain Policy and
>Def. DC Policy and that disabling them is bad. I haven't

found that to be
>the case. You just need to be aware of what the effects

are, as Mark
>indicates. If you set account policy, for example,

through the Default
>Domain Policy, and then you disable the DDP, that account

policy won't be
>undone--it just won't be change-able until you have

another domain-linked
>GPO available.
>
>--
>Darren Mar-Elia
>MS-MVP-Windows Management
>http://www.gpoguy.com
>
>
>
>"Mark Renoden [MSFT]" <(E-Mail Removed)>

wrote in message
>news:Obh%(E-Mail Removed)...
>> Hi Josh
>>
>> Effect is that Domain wide policy doesn't apply. It's

not a good thing to
>> do. Why the question?
>>
>> Kind regards
>> --
>> Mark Renoden [MSFT]
>> Windows Platform Support Team
>> Email: (E-Mail Removed)
>>
>> Please note you'll need to strip ".online" from my

email address to email
>> me; I'll post a response back to the group.
>>
>> This posting is provided "AS IS" with no warranties,

and confers no
>rights.
>>
>> "Josh" <(E-Mail Removed)> wrote in

message
>> news:27f0f01c4645c$16bc3b20$(E-Mail Removed)...
>> > All,
>> >
>> > Does anyone know what the effects are of disabling the
>> > default domain policy at the domain level?
>> >
>> > Thanks.

>>
>>

>
>
>.
>

 
Reply With Quote
 
Darren Mar-Elia
Guest
Posts: n/a
 
      8th Jul 2004
Josh-
Whatever was sent down to the DCs is still in place. Account policy is
stored locally on the DC, and its not one of those policies that gets
"un-tattoo'd" when you remove the GPO. If you fire up the local GPO editor
(gpedit.msc) on one of those DCs, you'll see the effective policy.

--
Darren Mar-Elia
MS-MVP-Windows Management
http://www.gpoguy.com



"Josh" <(E-Mail Removed)> wrote in message
news:29cce01c46509$dd55df40$(E-Mail Removed)...
> Well the reason I asked is because I have a domain were
> the default domain policy is disabled and no policy is
> linked to the domain. But there are still account lockout
> after a certain amount of bad tries. Where is this policy
> coming from?
> >-----Original Message-----
> >Josh-
> >That's assuming of course, that there isn't another GPO

> linked to the
> >domain. I've had this conversation with some other folks

> before and there is
> >this "fear" that there is something magical about the

> Def. Domain Policy and
> >Def. DC Policy and that disabling them is bad. I haven't

> found that to be
> >the case. You just need to be aware of what the effects

> are, as Mark
> >indicates. If you set account policy, for example,

> through the Default
> >Domain Policy, and then you disable the DDP, that account

> policy won't be
> >undone--it just won't be change-able until you have

> another domain-linked
> >GPO available.
> >
> >--
> >Darren Mar-Elia
> >MS-MVP-Windows Management
> >http://www.gpoguy.com
> >
> >
> >
> >"Mark Renoden [MSFT]" <(E-Mail Removed)>

> wrote in message
> >news:Obh%(E-Mail Removed)...
> >> Hi Josh
> >>
> >> Effect is that Domain wide policy doesn't apply. It's

> not a good thing to
> >> do. Why the question?
> >>
> >> Kind regards
> >> --
> >> Mark Renoden [MSFT]
> >> Windows Platform Support Team
> >> Email: (E-Mail Removed)
> >>
> >> Please note you'll need to strip ".online" from my

> email address to email
> >> me; I'll post a response back to the group.
> >>
> >> This posting is provided "AS IS" with no warranties,

> and confers no
> >rights.
> >>
> >> "Josh" <(E-Mail Removed)> wrote in

> message
> >> news:27f0f01c4645c$16bc3b20$(E-Mail Removed)...
> >> > All,
> >> >
> >> > Does anyone know what the effects are of disabling the
> >> > default domain policy at the domain level?
> >> >
> >> > Thanks.
> >>
> >>

> >
> >
> >.
> >



 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Default Domain Controller Policy and Default Domain Policy Paul D Microsoft Windows 2000 Group Policy 7 26th Oct 2004 01:12 AM
software restriction policy not working when running default domain policy from XP PC Gary Massengale Microsoft Windows 2000 Group Policy 2 24th Aug 2004 03:13 PM
Deleted Default Domain Controller Policy and Domain Policy - no backup James Microsoft Windows 2000 Group Policy 1 29th Apr 2004 04:40 PM
Error when changing Account Lockout policy for default domain policy Jeanne Microsoft Windows 2000 Active Directory 2 18th Nov 2003 12:22 AM
RE: TROUBLE: Missing Default Domain Policy and Default Domain Controller Policy content diasmith [MSFT] Microsoft Windows 2000 Active Directory 0 6th Oct 2003 08:44 PM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 07:10 AM.