Jump to content

Recommended Posts

Posted
my NM is having a thing about passwords and security. All admins are being demoted to domain admins, well thats just me and him. But I can add myself to the administrators security group at any time. how's that secure?
Posted
:? IMHO the problem exists between the network managers chair and keyboard if he wishes to 'demote' you to the highest level of access in a domain- Domain Admins group is automatically a member of every local Administrators group on every computer, including the DC...
Posted

Thats where I got a bit confused as to what he was trying to say actually I don't understand what they are supposedly being demoted from Enterprise Admins?

 

Or from local admins to domain admins dunno didn't actually make sense.

 

Ben

Posted
Emterprise Admins can Admin all domains in a Forest. Domain Admins can only Admin a single domain in a forest. This is entirely irrelevent for most schools as most people run a single domain in a single forest on one site. So Enterprise Admins and Domain Admins are functionally equivelent.
Posted
I presume you all use normal accounts for your every day to day operations and only use admin accounts when needed?

 

Ben

 

that is the intended idea. pretty much everything i do requires domain admin rights, dunno about administrator

 

Emterprise Admins can Admin all domains in a Forest. Domain Admins can only Admin a single domain in a forest. This is entirely irrelevent for most schools as most people run a single domain in a single forest on one site. So Enterprise Admins and Domain Admins are functionally equivelent.

 

i didnt realise that. whats the difference between domain admins and the administrators security group then?

Posted
Emterprise Admins can Admin all domains in a Forest. Domain Admins can only Admin a single domain in a forest. This is entirely irrelevent for most schools as most people run a single domain in a single forest on one site. So Enterprise Admins and Domain Admins are functionally equivelent.

 

i didnt realise that. whats the difference between domain admins and the administrators security group then?

Posted
whats the difference between domain admins and the administrators security group then

 

There's three 'Administrators' security groups. Do you mean Enterprise Admins, Domain Admins, or Administrators? It also depends on context. Do you mean on a member server/client or a Domain controller?

Posted

actually thats the least of my worries, i was just to make sense of policies being implemented over my head

 

trying to enable "password must meet complexity requirements" in group policy but its not working. not sure where im going wrong.

 

will try to explain what i've done

created a test OU with the attached normal staff policy

added another test policy which will contain the alterations im trying

created a test user in the test OU

 

enabled password complexity and minimum password length

in computer config/windows settings/security settings/account policies/password policy and loopback to force it to apply the computer settings to the user account

 

should work, but lets me put anything as the password.

Posted
Password complexity requirements have to be set in a GPO that applies to Domain controllers as its DC's that enforce the complexity requirements not the client PC/User. Typically this is done in the 'Default Domain Controller' GPO.
Posted

ah right. thanks.

 

the complexity issue. we've been asked to implement complex passwords as part of security required for outside access to staff email but the NM thinks that would be a nightmare for pupils as some have enough problems remembering non-complex passwords. I tend to agree.

 

its a bit of quandry because if we dont enforce complexity half the staff wont bother with it. And if we do half the kids wont be able to remember their passwords. any suggestions?

Posted

We have a multi domain forest primarily because of that issue.

 

There are a few packages out there that can get round this but I forget what they're called off hand. They are mentioned on this forum in a few places though.

Posted

that sounds complicated. i dont think we can do that.

 

Just a thought. if we applied complex passwords for everyone, will it force people with non-complex passwords to change them. even if we dont force them with the tick in group policy?

Posted
No, the password policy will only apply when they next change their password. That's why you also set a password expiration policy too.
Posted
can you not use loopback to make it apply to users, or does loopback only work the other way?

 

It's nothing to do with users! It's a computer policy. Loopback just lets you apply the User Configuration settings from the policies that are applied to your computer.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...