Jump to content

Recommended Posts

Posted

Hello All

 

Is it possible to use two password policies one domain eg staff with complex passwords and students with no passwords?

 

Many thanks for your help and advice.

 

Alex :D

Posted

we start our year 7 pupils off with the same password, 1 to 5, and then force them to change it at first logon. I worked in a place where staff were given the chance to change pupils passwords, and one teacher changed them all to "dog", which is the same as having no password at all. As you can imagine, folders started to disappear from pupil areas, work was copied and presented as their own work etc. but then again, I work in a secondary school.

beeswax

Posted

Thanks Beeswax

 

I should have mentioned that I am talking about a Primary school here. Sorry for the confusion.

 

Alex

Posted
Hello All

 

Is it possible to use two password policies one domain eg staff with complex passwords and students with no passwords?

 

Many thanks for your help and advice.

 

Alex :D

 

No. To have different password policies for different users you need to put them in seperate domains. This is what we have done.

Posted
No. To have different password policies for different users you need to put them in seperate domains. This is what we have done.

 

Cant you setup 2 different group policies with 2 different password policies(on the same domain that is)?

Posted
I'd say that you could set different account policies in a GPO attached to an OU. The only policy that has to come from the default domain policy is the Kerberos Policy.
Posted
No. Account policies are per domain. See MS article here. Believe me, if they weren't I wouldn't have gone to the trouble of setting up such an elaborate system.
Posted

You could be right there - although the wording from MS does not make it clear.

 

I'm wondering now what else is Default Domain Policy Only?

Posted
When you configure account policies (such as password policy and account lockout policy) in Active Directory, Microsoft Windows 2000 permits only one domain account policy per domain.

 

Seems fairly unambiguous to me. I'm pretty sure that its just account policies that are set per domain. Everything else can be set on the OU level :)

Posted
Ah yes.. duh oh yes now i remember.. Password Policies are set at domain level. Looks like me grey matter is starting to go :?
Posted
For 2000 - clear as day but 2003 manual not so clear :p But 'Inside AD 2nd edition by Sakari Kouti - Mika Seitsonen' puts it in plain english :)
Posted

Policies are per domain if you stick to the pure microsoft aproach. You can however install a custom GINA which will intercept password changes and allow you to apply your own policy based on whatever criteria you see fit.

 

It is mildly frightening, but there are even open source projects. Google for custom gina and check out sourceforge for the open source stuff. It is also used as a method of synchronising password changes with non MS systems by notifying them of password events.

 

One of the big projects is called pGINA which seems stable and reputable, but beware, there are trojan GINAs out there which will just capture passwords (fun to play with though)

Posted

It appears to just drop a token in the users pen drive that contains an encrypted username password combo - the existing username & password work as before so lost keys and external access have the same restrictions as previously.

 

Having installed it at home this PM (yes sad I know) I think the interface is clunky and might not be very scaleable - it might make a good way of creating a token for users to reset theit own password on an unmanned unlock station though.

 

I have to get my daughter to let me install it on her machine now so that I can see how it works across the domain.

 

One quick downside - as written it seems to only allow the local admin account to unlock the machine (other than the logged in user)

 

I like the idea though - makes me wish I could program at that level - a bit to low level for VBS to cut it I think :-)

Posted

I seem to be monopolising this thread a bit - sorry - but I remember seeing the answer to this problem a few years back on the web, do you think I can find it now though?

 

Addressing the original problem of differing password policies for different users, I have found the following (paid for :-( ) product which on the face of it does what you are asking for. It might be worth a look

 

Password Policy Enforcer

 

I am going to keep trying to find the free solution I know was out there - I may be some time...

  • 2 months later...
Posted
Is it possible to use two password policies one domain eg staff with complex passwords and students with no passwords?

 

I'm pretty sure the complex password policy is only enforced when you try and CHANGE a password. As you said, pupils don't have a password so will never need to change it.

So why not switch off the complex password policy, create all your pupil users, switch it back on then do a 'force users to change password next logon' for your staff users.

It might even be simpler than that: does windows apply the complex password policy when admins change passwords? If not, then you can leave the policy switched on all the time.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...