Jump to content

Recommended Posts

Posted

Hi all,

 

All users get locked out after 3 failed logon attempts. I want to change this number to hopefully reduce the number of students locking themselves out.

 

I can't locate the setting in the GPOs.

 

Does anyone have a method to search all GPOs for this setting?

 

Location

GPO_name\Computer Configuration\Windows Settings\Security Settings\Account Policies\Account Lockout Policy

 

Thanks.

Theo

Posted

If you use the Group Policy Management Console, you can run a Group Policy Modeling or a Group Policy Results request to find out which policy is applying the setting.

 

Generally this is contained in the Default Domain Policy though.

Posted

Thanks all for your replies however it seems it isn't listed in any GPO...

The policy has been in place for many years before we introduced 2012 DCs so it wouldn't be in there..

 

Anywhere else it could be?

Posted
Thanks all for your replies however it seems it isn't listed in any GPO...

The policy has been in place for many years before we introduced 2012 DCs so it wouldn't be in there..

 

Anywhere else it could be?

 

Check your Default Domain Policy. Even though they maybe new DC's they will keep the same policies if the Domain Controllers were upgraded.

Posted
Check your Default Domain Policy. Even though they maybe new DC's they will keep the same policies if the Domain Controllers were upgraded.

 

I've checked it.. nothing in there! Mystery...

Posted

You may have fine grained password policies in place.

 

Open ADSI Edit, go to the default naming context, CN=System -->CN=Password Settings Container

 

fgpp.png

 

If there is something there, get its properties and go to the msDS-PSOAppliesTo property. Under there, there should be a DN to a group listed.

 

pwpolicy.png

Posted
You may have fine grained password policies in place.

 

Open ADSI Edit, go to the default naming context, CN=System -->CN=Password Settings Container

 

[ATTACH=CONFIG]38960[/ATTACH]

 

If there is something there, get its properties and go to the msDS-PSOAppliesTo property. Under there, there should be a DN to a group listed.

 

[ATTACH=CONFIG]38961[/ATTACH]

 

 

Thanks for the info.

 

There is a CN=Directorate PSO in that container but the msDS-PSOAppliesTo is not set. I can only assume this is for Direcorate and not all users whoever set it up.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...