Password complexity rules not being applied

H

Hank Arnold

I've updated my password config in the default GPO. It has the policies
enabled for complex passwords as well as the number of logon tries before
disabling the account. Neither is being enforced.

1) Any suggestions as to where to look?

2) Is there a command line way to set the policy? I was ale to use a command
line to set the rest of the policies, but this one wasn't in the list.
 
P

ptwilliams

How long have you waited. You more than likely made the change to the GPO
on the PDCe. This change needs to replicate and be applied to the DC that
you are authenticating against (well, apply GPO from anyway ;-)

Intrasite: 5 mins for replication (15 if you've a large mesh) and another 5
mins for policy application. Then logon and see if it's enforced...


--

Paul Williams

http://www.msresource.net/
http://forums.msresource.net/
 
T

Tomasz Onyszko [MVP]

Hank said:
I've updated my password config in the default GPO. It has the policies
enabled for complex passwords as well as the number of logon tries before

What do You mean by "default GPO"? You should modify password polic in
Default domain policy
 
M

mark

Too elaborate on Tomasz's comment:

While the settings for password complexity are in the GPO template and
can be set at any OU level, they only take effect if set at the domain
level. You should set the password complexity level in the default
domain policy. Unfortunately you can only have one password complexity
setting per domain.

/mark
 
H

Hank Arnold

I'm getting to the settings the following way:

- Log onto the DC as Administrator
- Open Active Directory Users & Computers
- Right click on "Hospice.Local" domain name
- Select Properties
- Select Group Policy tab
- Edit "Default Domain Policy" (currently the only one)
- Select Computer Configuration
Windows settings
Security Settings
Account Policies
Password Policy

This is where the complexity rule is "enabled". Is this the correct place to
do it?

I should also mention that the "Account Lockout Policy" is set for a
threshold of 5 attempts. Currently the system is ignoring that setting,
also.....
 
H

Hank Arnold

Thanks for the input.

I'll take a look Monday AM when I get to work. There are no other GPOs
listed other than the Default one. What kind of events should I be looking
for? Where should I turn on the userenv logging?
 
H

Hank Arnold

Thanks again for your inputs.

I was able to RDP in and check it out. There are no errors or warnings for
userenv and only Event 1704 (GPO applied successfully) in the Application
log for SceCli.

I checked the registry and found that the setting is for both VERBOSE and
LOGFILE. I do have the files Userenv.log and Userenv.bak. Is there anything
in there that could give a clue?
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top