Jump to content

Recommended Posts

Posted

Hi,

We have forced for September staff to change their network password, which the force is working fine.

 

However it allows them to keep the same password.

 

I have set in the staff only group policy to remember 2 passwords. The problem been its under computer configuration and doing it on a user account - isn't this bad practice? Does it work ok? As it doesn't seem to work for us.

 

THanks

Guest TheLibrarian
Posted

Some password settings are set on the Default Domain policy and only there.

 

This effectively means you can only have differing password policies on different domains IIRC.

 

This may not be true for later versions of Windows Server later than W2K, however I haven't looked this up.

Guest TheLibrarian
Posted

Excerpt from :Enforcing Strong Password Usage Throughout Your Organization

 

There can be only a single password policy for each account database. An Active Directory domain is considered a single account database, as is the local account database on stand alone computers. Computers that are members of a domain also have a local account database, but most organizations that have deployed Active Directory domains require their users to log on to their computers and the network by using domain-based accounts. Consequently if you specify a minimum password length of 14 characters for a domain, all users in the domain must use passwords of 14 or more characters when they create new passwords. To establish different requirements for a specific set of users, you must create a new domain for their accounts.

 

 

In essence, one password policy per domain as far as I understand it.

Posted

As TheLibrarian says, one password policy for one Server 2003 domain. You cannot have OU level password policies in Server 2003.

 

I believe this changes in Server 2008 and OU level password policies are possible - but as I haven't got that far yet... * waits for someone else to confirm or deny * :)

Posted

That's correct. Windows 2000/2003 Server is one password policy per domain. I believe there are some third party tools which add this function, but 2008 Server does allow password policies per OU anyway, so you may as well upgrade to 2008 Server.

 

As a recommendation, the number of remembered passwords should be at least 10 for it to be of any great use. You can also configure a policy (forget its name top of my head), where users can be reminded x amount of days to change it before the deadline. It's linked with how many days passwords are valid for.

Posted
2008 Server does allow password policies per OU anyway

 

Not quite.. unlesss I've missed some enhancement, you apply them to users and|or groups. They're a bit of a pain (MS have you make them with ADSIEdit etc.), but there are a few 3rd party freebie GUIs to get around that.

Posted
Not quite.. unlesss I've missed some enhancement, you apply them to users and|or groups.

 

Sorry I did use the wrong terminology, it's just generally speaking you do have a GPO per OU.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...