Jump to content

Recommended Posts

Posted

Is it possible to set different password policies for different OUs in AD in server 2003 or does the domain level group policy set all this. We are wanting to enforce tighter passwords for staff. I know that if we enable it for the whole domain the kids are going to find it hard to log on.

 

Tim

Posted
As elsiegee says, password policies are domain wide in Server 2003, so you either have to have a second domain or you could update to Server 2008 which allows multiple security policies.
Posted
If i upgrade to 2008, will i only need to upgrade the one server for the Group Policy settings to be copied over or will i need to upgrade all the DCs to 2008?
Posted
If i upgrade to 2008, will i only need to upgrade the one server for the Group Policy settings to be copied over or will i need to upgrade all the DCs to 2008?

 

I'm not 100% sure. But I believe if you upgrade the main DC, the others have their schemas updated. The only issue would be the management tools, as 2008 has a new format of tools, compared to the old .msc files.

Posted

Officially, and according to all available literature, you can only have one Password Policy per domain...

 

But.. I have seen an explanation of how to do this.. I can't find where it was now... google is failing me ...

 

It was something to do with changing the security on the domain level policy.

You have one that only staff can access, and another that only students can access, I think it means you can't have users in both groups.

 

I will have another look around, it may have been on a whitepaper I got from somewhere, so it'll be at work.

Posted

Password policy is applied per domain, or per subdomain...

 

So you could theoretically create a subdomain for staff, and a subdomain for pupils and apply differing password policies there.

 

EG If your domain was myschool.com you could create students.myschool.com and apply a lax password policy here, and staff.myschool.com and create a strict passwoird policy here. Of course, the relavent users need to be located in the correct subdomains.

Posted

As already mentioned you have two choices - running 2003 server, you can create a child domain which allows different password policies or alternatively 2008 server allows you to do this per OU.

 

If I had the choice, I would upgrade to 2008 server. A much simpler solution and more tools to play around with. I would highly recommend ALL servers run 2008, unless there's a specific reason you cannot do this?

Posted

For the password policies to be applied in Server 2008 the domain level needs to be raised to 2008, which you can't do whilst you have 2003 DCs.

 

I'm currently running at 2008 domain level and was an fairly painless upgrade process. Just make sure you test it a couple of times first in a VM.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...