ictex Posted March 7, 2006 Posted March 7, 2006 Hello All Is it possible to use two password policies one domain eg staff with complex passwords and students with no passwords? Many thanks for your help and advice. Alex
beeswax Posted March 7, 2006 Posted March 7, 2006 we start our year 7 pupils off with the same password, 1 to 5, and then force them to change it at first logon. I worked in a place where staff were given the chance to change pupils passwords, and one teacher changed them all to "dog", which is the same as having no password at all. As you can imagine, folders started to disappear from pupil areas, work was copied and presented as their own work etc. but then again, I work in a secondary school. beeswax
ictex Posted March 7, 2006 Author Posted March 7, 2006 Thanks Beeswax I should have mentioned that I am talking about a Primary school here. Sorry for the confusion. Alex
Norphy Posted March 7, 2006 Posted March 7, 2006 Hello All Is it possible to use two password policies one domain eg staff with complex passwords and students with no passwords? Many thanks for your help and advice. Alex No. To have different password policies for different users you need to put them in seperate domains. This is what we have done.
apeo Posted March 7, 2006 Posted March 7, 2006 No. To have different password policies for different users you need to put them in seperate domains. This is what we have done. Cant you setup 2 different group policies with 2 different password policies(on the same domain that is)?
ChrisH Posted March 7, 2006 Posted March 7, 2006 No Norphy is correct the password policy is for the whole domain only.
alan-d Posted March 7, 2006 Posted March 7, 2006 I'd say that you could set different account policies in a GPO attached to an OU. The only policy that has to come from the default domain policy is the Kerberos Policy.
Norphy Posted March 7, 2006 Posted March 7, 2006 No. Account policies are per domain. See MS article here. Believe me, if they weren't I wouldn't have gone to the trouble of setting up such an elaborate system.
alan-d Posted March 7, 2006 Posted March 7, 2006 You could be right there - although the wording from MS does not make it clear. I'm wondering now what else is Default Domain Policy Only?
Norphy Posted March 7, 2006 Posted March 7, 2006 When you configure account policies (such as password policy and account lockout policy) in Active Directory, Microsoft Windows 2000 permits only one domain account policy per domain. Seems fairly unambiguous to me. I'm pretty sure that its just account policies that are set per domain. Everything else can be set on the OU level
apeo Posted March 7, 2006 Posted March 7, 2006 Ah yes.. duh oh yes now i remember.. Password Policies are set at domain level. Looks like me grey matter is starting to go :?
alan-d Posted March 7, 2006 Posted March 7, 2006 For 2000 - clear as day but 2003 manual not so clear But 'Inside AD 2nd edition by Sakari Kouti - Mika Seitsonen' puts it in plain english
Shiny_Guru Posted March 10, 2006 Posted March 10, 2006 Policies are per domain if you stick to the pure microsoft aproach. You can however install a custom GINA which will intercept password changes and allow you to apply your own policy based on whatever criteria you see fit. It is mildly frightening, but there are even open source projects. Google for custom gina and check out sourceforge for the open source stuff. It is also used as a method of synchronising password changes with non MS systems by notifying them of password events. One of the big projects is called pGINA which seems stable and reputable, but beware, there are trojan GINAs out there which will just capture passwords (fun to play with though)
Shiny_Guru Posted March 12, 2006 Posted March 12, 2006 Some idle googling trying to find the site I remembered revealed this site http://www.rohos.com/welcome-screen/usbflash.htm Which seems a very interesting idea - I shall probably play with it later but it might be worth you taking a look - if the user does not have to remember a password it can be as complex as you want with no worries
alan-d Posted March 12, 2006 Posted March 12, 2006 Nice idea - a throwback to the smartcard system. But how would it work if we wanted the kids to log into their account from home?
Shiny_Guru Posted March 12, 2006 Posted March 12, 2006 It appears to just drop a token in the users pen drive that contains an encrypted username password combo - the existing username & password work as before so lost keys and external access have the same restrictions as previously. Having installed it at home this PM (yes sad I know) I think the interface is clunky and might not be very scaleable - it might make a good way of creating a token for users to reset theit own password on an unmanned unlock station though. I have to get my daughter to let me install it on her machine now so that I can see how it works across the domain. One quick downside - as written it seems to only allow the local admin account to unlock the machine (other than the logged in user) I like the idea though - makes me wish I could program at that level - a bit to low level for VBS to cut it I think :-)
Shiny_Guru Posted March 12, 2006 Posted March 12, 2006 I seem to be monopolising this thread a bit - sorry - but I remember seeing the answer to this problem a few years back on the web, do you think I can find it now though? Addressing the original problem of differing password policies for different users, I have found the following (paid for :-( ) product which on the face of it does what you are asking for. It might be worth a look Password Policy Enforcer I am going to keep trying to find the free solution I know was out there - I may be some time...
W32Jbot Posted May 24, 2006 Posted May 24, 2006 we are looking at using this >>> http://www.specopssoft.com/ It does exactly what you are looking for, 2 policies 1 domain
eean Posted May 25, 2006 Posted May 25, 2006 Is it possible to use two password policies one domain eg staff with complex passwords and students with no passwords? I'm pretty sure the complex password policy is only enforced when you try and CHANGE a password. As you said, pupils don't have a password so will never need to change it. So why not switch off the complex password policy, create all your pupil users, switch it back on then do a 'force users to change password next logon' for your staff users. It might even be simpler than that: does windows apply the complex password policy when admins change passwords? If not, then you can leave the policy switched on all the time.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now