Welcome, Register for free! or Login below:
EduGeek.net RSS Feeds Register FAQ Members Social Groups User Map Calendar Search Today's Posts Mark Forums Read

Notices

Windows

Windows forum sponsored by

For all of your Windows problems

Go Back   EduGeek.net Forums > Technical > Windows
Reply
 
LinkBack Thread Tools Search Thread Language
Sponsored Links
Old 08-11-2007, 03:04 PM   #1
 
timbo343's Avatar
 
Join Date: Dec 2005
Location: Leeds/York area, North Yorkshire
Posts: 905
Thanks: 8
Thanked 19 Times in 18 Posts
Rep Power: 11 timbo343 will become famous soon enough
Send a message via MSN to timbo343
Default password complexity help

We are trying to enforce password complexity into our domain but dont want to enforce it for pupils. Looking and testing the settings on the servers, it looks like it can only be done at domain level not OU level. Is there a way we can configure this per OU? It can be done via password filtering but it means eidting the registry on each DC and i dont particually want do that. is there an easier way?

Thanks in advance

Tim
  Reply With Quote
Old 08-11-2007, 03:06 PM   #2
 
Gatt's Avatar
 
Join Date: Jan 2006
Location: Moorside High, Swinton / Middleton, Rochdale
Posts: 2,156
uk uk scotland
Thanks: 82
Thanked 38 Times in 28 Posts
Rep Power: 19 Gatt is a jewel in the roughGatt is a jewel in the roughGatt is a jewel in the rough
Send a message via MSN to Gatt
Default Re: password complexity help

Unfortunately - No

Password Policies are set at the domain level and only take effect in the Default Domain Policy.

Only solution would be seperate domains for pupils and staff..
  Reply With Quote
Old 08-11-2007, 03:13 PM   #3
 
ajbritton's Avatar
 
Join Date: Jul 2005
Location: Wandsworth
Posts: 1,414
Thanks: 7
Thanked 15 Times in 10 Posts
Rep Power: 11 ajbritton will become famous soon enough
Default Re: password complexity help

Quote:
Originally Posted by Gatt
Unfortunately - No

Password Policies are set at the domain level and only take effect in the Default Domain Policy.

Only solution would be seperate domains for pupils and staff..
Be careful how loud you say that... hang on... what's that noise ... oh no! ... here they come... IT'S THE YOU MUST USE A SINGLE DOMAIN gang..... :P
  Reply With Quote
Old 08-11-2007, 03:19 PM   #4
 
Norphy's Avatar
 
Join Date: Jan 2006
Location: Dunstable
Posts: 1,032
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 0 Norphy is an unknown quantity at this point
Send a message via MSN to Norphy
Default Re: password complexity help

My last place used multiple domains for precisely this reason. And about a month after I set that up, I found about this.

I swore.
  Reply With Quote
Old 08-11-2007, 03:21 PM   #5
 
ajbritton's Avatar
 
Join Date: Jul 2005
Location: Wandsworth
Posts: 1,414
Thanks: 7
Thanked 15 Times in 10 Posts
Rep Power: 11 ajbritton will become famous soon enough
Default Re: password complexity help

Did you find out how much it costs?
  Reply With Quote
Old 08-11-2007, 03:24 PM   #6
 
Norphy's Avatar
 
Join Date: Jan 2006
Location: Dunstable
Posts: 1,032
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 0 Norphy is an unknown quantity at this point
Send a message via MSN to Norphy
Default Re: password complexity help

No but I suspect it's not cheap.
  Reply With Quote
Old 08-11-2007, 03:31 PM   #7
 
ajbritton's Avatar
 
Join Date: Jul 2005
Location: Wandsworth
Posts: 1,414
Thanks: 7
Thanked 15 Times in 10 Posts
Rep Power: 11 ajbritton will become famous soon enough
Default Re: password complexity help

That would be my guess as well. Unless of course they do academic pricing.
  Reply With Quote
Old 08-11-2007, 03:31 PM   #8
 
plexer's Avatar
 
Join Date: Dec 2005
Location: Norfolk
Posts: 4,133
uk
Thanks: 30
Thanked 93 Times in 92 Posts
Rep Power: 32 plexer is a glorious beacon of lightplexer is a glorious beacon of lightplexer is a glorious beacon of lightplexer is a glorious beacon of lightplexer is a glorious beacon of lightplexer is a glorious beacon of light
Default Re: password complexity help

Well I'll found out when they get back to me.

Ben
  Reply With Quote
Old 08-11-2007, 03:32 PM   #9
 
Gatt's Avatar
 
Join Date: Jan 2006
Location: Moorside High, Swinton / Middleton, Rochdale
Posts: 2,156
uk uk scotland
Thanks: 82
Thanked 38 Times in 28 Posts
Rep Power: 19 Gatt is a jewel in the roughGatt is a jewel in the roughGatt is a jewel in the rough
Send a message via MSN to Gatt
Default Re: password complexity help

Shame, cos their GPUpdate tools were great - espcially with them being free and all..
  Reply With Quote
Old 08-11-2007, 05:33 PM   #10
 
Kyle's Avatar
 
Join Date: Jan 2006
Posts: 768
Thanks: 30
Thanked 0 Times in 0 Posts
Rep Power: 0 Kyle is an unknown quantity at this point
Default Re: password complexity help

Easy Solution here.

Set the Policy,
Got to a OU with Pupils
Select all of them, then right click properties,
choose password never expires.

This will stop the pupils passwords ever expiring. Do this for all pupils/users you don't want passwords expiring for.

I have used this successfully before.

You can still go in a change the password for them or use a script to force users from a certain OU choose a different password at next log on.
  Reply With Quote
Old 08-11-2007, 05:40 PM   #11
 
FN-GM's Avatar
 
Join Date: Jun 2007
Location: Rochdale, Lancashire
Posts: 4,927
uk
Thanks: 157
Thanked 162 Times in 156 Posts
Rep Power: 38 FN-GM is a splendid one to beholdFN-GM is a splendid one to beholdFN-GM is a splendid one to beholdFN-GM is a splendid one to beholdFN-GM is a splendid one to beholdFN-GM is a splendid one to beholdFN-GM is a splendid one to behold
Send a message via Skype™ to FN-GM
Default Re: password complexity help

Quote:
Originally Posted by Kyle
Easy Solution here.

Set the Policy,
Got to a OU with Pupils
Select all of them, then right click properties,
choose password never expires.

This will stop the pupils passwords ever expiring. Do this for all pupils/users you don't want passwords expiring for.

I have used this successfully before.

You can still go in a change the password for them or use a script to force users from a certain OU choose a different password at next log on.
He doesn't want the users passwords not to expire he wants to set a policy on certain users on how complex there passwords are
  Reply With Quote
Old 08-11-2007, 05:43 PM   #12
 
ajbritton's Avatar
 
Join Date: Jul 2005
Location: Wandsworth
Posts: 1,414
Thanks: 7
Thanked 15 Times in 10 Posts
Rep Power: 11 ajbritton will become famous soon enough
Default Re: password complexity help

Quote:
Originally Posted by Kyle
Easy Solution here.

Set the Policy,
Got to a OU with Pupils
Select all of them, then right click properties,
choose password never expires.

This will stop the pupils passwords ever expiring. Do this for all pupils/users you don't want passwords expiring for.

I have used this successfully before.

You can still go in a change the password for them or use a script to force users from a certain OU choose a different password at next log on.
This will work if you change the passwords manually via DSA.MSC, but if you configure the 'force password change' attribute, then the password policy will be applied.
  Reply With Quote
Old 15-11-2007, 01:03 PM   #13
 
plexer's Avatar
 
Join Date: Dec 2005
Location: Norfolk
Posts: 4,133
uk
Thanks: 30
Thanked 93 Times in 92 Posts
Rep Power: 32 plexer is a glorious beacon of lightplexer is a glorious beacon of lightplexer is a glorious beacon of lightplexer is a glorious beacon of lightplexer is a glorious beacon of lightplexer is a glorious beacon of light
Default Re: password complexity help

For 850 users in 1 AD domain the price is:

£1461.25

2nd and 3rd maintenance combined is £500

Ben
  Reply With Quote
Old 15-11-2007, 08:41 PM   #14
 
PiqueABoo's Avatar
 
Join Date: Jan 2006
Posts: 500
Thanks: 1
Thanked 20 Times in 16 Posts
Rep Power: 10 PiqueABoo will become famous soon enoughPiqueABoo will become famous soon enough
Default Re: password complexity help

Quote:
the price is:
OUCH!

I did a password filter a long time ago (as usual) which tested them against a memory mapped dictionary file and definitely wasn't hard.

Multiple password policies is more complex because you need to need get hold of an OU or group membership from an account name in order to pick and test their proposed password against the right policy. That means talking to AD and in this context I'm currently not sure which of several userland approaches to that might work or be be safe, but it can't be that hard!

Anyway at that price I'd probably hold fire on a solution now and start considering whether it might be an idea to just upgrade DCs to Server 2008 next summer.

Well not me personally, I'm actually wondering whether to have a quick look at this and knock one out at a bargain basement price.
  Reply With Quote
Old 15-11-2007, 09:23 PM   #15
 
mrcrazy04's Avatar
 
Join Date: Nov 2006
Location: Bedfordshire/Dundee, UK
Posts: 173
uk uk scotland
Thanks: 0
Thanked 3 Times in 3 Posts
Rep Power: 5 mrcrazy04 is on a distinguished road
Default Re: password complexity help

If you got an open source GINA dll, then you could integrate it into that to do the lookups and apply the relevant policy - and then it isn't running in userland.
  Reply With Quote
Reply

Register now for FREE and post messages!


Username: Password: Confirm Password: E-Mail: Confirm E-Mail:
Birthday:      
Image Verification
  I agree to forum rules 

Similar Threads
Thread Thread Starter Forum Replies Last Post
Password Protect USB Key sqdge Windows 2 31-07-2007 03:47 PM
That is the right password! Ric_ *nix 9 27-07-2007 09:23 AM
Lanview password kevin Network and Classroom Management 4 17-05-2007 02:14 PM
Bios Password jamieallonby Hardware 16 10-03-2006 01:45 PM
Password Security mark School ICT Policies 5 14-10-2005 03:39 PM



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search Thread
Search Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT +1. The time now is 09:12 PM.
Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 ©2008, Crawlability, Inc.
Copyright EduGeek.net