Jump to content

Recommended Posts

Posted

Afternoon All,

 

Not sure if I'm being a spas today, or whether things that I thought had changed haven't actually changed, but password policies!

 

Currently the default domain policy isn't used for anything and inheritance is blocked (original setting before I joined here), so I made a new password policy at a lower level for this, but some people don't seem to get it applied to them. Does this still not work even in 2012r2? Set a 90 day timer on it, and it's showing as an applied GPO to the computers, but a user is getting a 14 day warning after 16 days. (Which would be the 30 set in the Domain policy)

 

I know this never used to work pre08 but thought it was all sorted now, or do I need to look at fine grained policies under the Default Domain is unblocked?

 

Thanks,

Steve

Posted (edited)
It still needs to be in default policy but you can use the fine grained password policy settings instead in ADAC Edited by Sagima
wrong terminology
  • Thanks 1
Posted

That's rather spassy :( Guess I need to go dig through the Domain Policy and see why they blocked inheritance to all OUs for it... :s

 

Thanks,

Steve

Posted

Hmm guess that might make more sense rather than trying to work out what bit of the DDP was blocked and for what reason :) Will have a flick through that!

 

Thanks,

Steve

Posted

I'd still certainly looks at why the DDP was blocked. That's definitely bad practice.

 

In fact we have our DDP enforced to override any blocks

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...