karldenton Posted July 23, 2009 Posted July 23, 2009 Hi, We have forced for September staff to change their network password, which the force is working fine. However it allows them to keep the same password. I have set in the staff only group policy to remember 2 passwords. The problem been its under computer configuration and doing it on a user account - isn't this bad practice? Does it work ok? As it doesn't seem to work for us. THanks
Guest TheLibrarian Posted July 23, 2009 Posted July 23, 2009 Some password settings are set on the Default Domain policy and only there. This effectively means you can only have differing password policies on different domains IIRC. This may not be true for later versions of Windows Server later than W2K, however I haven't looked this up.
karldenton Posted July 23, 2009 Author Posted July 23, 2009 The settings are in computer configuration in all OU's but doesn't seem to work after a gpupdate /force
strawberry Posted July 23, 2009 Posted July 23, 2009 they're there, but they wont take effect, only from the default domain policy i'm afriad. Only way round it is to setup a sub domain or upgrade to 2008
Guest TheLibrarian Posted July 23, 2009 Posted July 23, 2009 Excerpt from :Enforcing Strong Password Usage Throughout Your Organization There can be only a single password policy for each account database. An Active Directory domain is considered a single account database, as is the local account database on stand alone computers. Computers that are members of a domain also have a local account database, but most organizations that have deployed Active Directory domains require their users to log on to their computers and the network by using domain-based accounts. Consequently if you specify a minimum password length of 14 characters for a domain, all users in the domain must use passwords of 14 or more characters when they create new passwords. To establish different requirements for a specific set of users, you must create a new domain for their accounts. In essence, one password policy per domain as far as I understand it.
elsiegee40 Posted July 23, 2009 Posted July 23, 2009 As TheLibrarian says, one password policy for one Server 2003 domain. You cannot have OU level password policies in Server 2003. I believe this changes in Server 2008 and OU level password policies are possible - but as I haven't got that far yet... * waits for someone else to confirm or deny *
Michael Posted July 23, 2009 Posted July 23, 2009 That's correct. Windows 2000/2003 Server is one password policy per domain. I believe there are some third party tools which add this function, but 2008 Server does allow password policies per OU anyway, so you may as well upgrade to 2008 Server. As a recommendation, the number of remembered passwords should be at least 10 for it to be of any great use. You can also configure a policy (forget its name top of my head), where users can be reminded x amount of days to change it before the deadline. It's linked with how many days passwords are valid for.
PiqueABoo Posted July 23, 2009 Posted July 23, 2009 2008 Server does allow password policies per OU anyway Not quite.. unlesss I've missed some enhancement, you apply them to users and|or groups. They're a bit of a pain (MS have you make them with ADSIEdit etc.), but there are a few 3rd party freebie GUIs to get around that.
Michael Posted July 24, 2009 Posted July 24, 2009 Not quite.. unlesss I've missed some enhancement, you apply them to users and|or groups. Sorry I did use the wrong terminology, it's just generally speaking you do have a GPO per OU.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now