enjay Posted August 13, 2019 Posted August 13, 2019 My predecessor defined a password policy via the "Default Domain Policy" GPO, which is a bit high-level for my liking as I'd like to have different rules for staff and students. Can I just delete the settings from the Default Domain Policy and re-apply via new Policies at my chosen level, or will that upset something? I know the Default Domain Policy can be finicky sometimes.
FishCustard Posted August 13, 2019 Posted August 13, 2019 You'll want to use Fine-Grained Password Policies for that: https://blogs.technet.microsoft.com/canitpro/2013/05/29/step-by-step-enabling-and-using-fine-grained-password-policies-in-ad/
MartinT Posted August 13, 2019 Posted August 13, 2019 Best practice is to keep the default domain policy empty, and place your default company policy next to it. I have seen a network go severely inoperative when the default GPO is screwed in any way. 1
FishCustard Posted August 13, 2019 Posted August 13, 2019 I believe there are some domain-wide settings (like a global password policy) that can only be configured in the Default Domain Policy - other than for those settings however, what you say is good advice.
HPlum78 Posted August 13, 2019 Posted August 13, 2019 Yep ms have a tool that restores your default domain and default domain controller gpos back to their default settings.
enjay Posted August 13, 2019 Author Posted August 13, 2019 You'll want to use Fine-Grained Password Policies for that: https://blogs.technet.microsoft.com/canitpro/2013/05/29/step-by-step-enabling-and-using-fine-grained-password-policies-in-ad/ That's how we did password policy at my last school too. So, should I remove the settings from the Default Domain Policy then create PSOs instead?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now