Nausing Posted October 5, 2016 Posted October 5, 2016 Hi all, All users get locked out after 3 failed logon attempts. I want to change this number to hopefully reduce the number of students locking themselves out. I can't locate the setting in the GPOs. Does anyone have a method to search all GPOs for this setting? Location GPO_name\Computer Configuration\Windows Settings\Security Settings\Account Policies\Account Lockout Policy Thanks. Theo
DJ-1701 Posted October 5, 2016 Posted October 5, 2016 If you use the Group Policy Management Console, you can run a Group Policy Modeling or a Group Policy Results request to find out which policy is applying the setting. Generally this is contained in the Default Domain Policy though.
Davit2005 Posted October 5, 2016 Posted October 5, 2016 Maybe set at the Default Domain Policy unless you have anything special set.
Steve21 Posted October 5, 2016 Posted October 5, 2016 Did you check in ADAC if it's 2012? Might not be a GPO Steve
Nausing Posted October 5, 2016 Author Posted October 5, 2016 Thanks all for your replies however it seems it isn't listed in any GPO... The policy has been in place for many years before we introduced 2012 DCs so it wouldn't be in there.. Anywhere else it could be?
Davit2005 Posted October 5, 2016 Posted October 5, 2016 Thanks all for your replies however it seems it isn't listed in any GPO... The policy has been in place for many years before we introduced 2012 DCs so it wouldn't be in there.. Anywhere else it could be? Check your Default Domain Policy. Even though they maybe new DC's they will keep the same policies if the Domain Controllers were upgraded.
Nausing Posted October 5, 2016 Author Posted October 5, 2016 Check your Default Domain Policy. Even though they maybe new DC's they will keep the same policies if the Domain Controllers were upgraded. I've checked it.. nothing in there! Mystery...
Norphy Posted October 5, 2016 Posted October 5, 2016 You may have fine grained password policies in place. Open ADSI Edit, go to the default naming context, CN=System -->CN=Password Settings Container If there is something there, get its properties and go to the msDS-PSOAppliesTo property. Under there, there should be a DN to a group listed.
Nausing Posted October 5, 2016 Author Posted October 5, 2016 You may have fine grained password policies in place. Open ADSI Edit, go to the default naming context, CN=System -->CN=Password Settings Container [ATTACH=CONFIG]38960[/ATTACH] If there is something there, get its properties and go to the msDS-PSOAppliesTo property. Under there, there should be a DN to a group listed. [ATTACH=CONFIG]38961[/ATTACH] Thanks for the info. There is a CN=Directorate PSO in that container but the msDS-PSOAppliesTo is not set. I can only assume this is for Direcorate and not all users whoever set it up.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now