Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: Group Policy: multiple password policies in the same domain? |
|---|---|
| Date: | Wed, 31 Aug 2005 10:47:49 -0400 |
-----Original Message----- From: Beauford, Jason [mailto:jbeauford@EightInOnePet.com] Sent: Wednesday, August 31, 2005 10:26 AM To: Derick Anderson; focus-ms@securityfocus.com Subject: RE: Group Policy: multiple password policies in the same domain? Domain Wide Password policies cannot be blocked by OU Policies. With that in mind you should look at creating an OU and setting up a GPO with Password Policies there rather than on the top level domain. Drop your service accounts into the OU and they will take on the the applied GPO. Because you have no other password policy set on the top level domain name, your "other" users will be unaffected. I believe that should do it. But then again. I haven't tested it or ever implemented it to confirm. Check it out. JMB
I've tried this and the end result is that the policy is undefined. Someone else mentioned that it would only affect local accounts (local security policy overridden by Group Policy). Since domain controllers have no local accounts, it would make sense (unfortunately for me) that whatever password policy the domain controllers were given would determine the domain password policy. The service accounts I want to harden are domain accounts, not local ones. I can't use local accounts because some of them must transfer data from one machine to the other. I've tried using Group Policy modeling with security filtering (i.e., apply only to 'service accounts' group), and that is not applied. If I add 'Domain Computers' to that list then it applies but conflicts with the domain password policy and nothing is set. I don't understand how applying it to specific servers will affect domain user accounts but that is one thing I have yet to try. Also thanks to those people who've mailed me off-list for your replies. Derick Anderson --------------------------------------------------------------------------- ---------------------------------------------------------------------------
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: Group Policy: multiple password policies in the same domain?, Derick Anderson |
|---|---|
| Next by Date: | Re: Active Directory password external use, Matthew Farrenkopf |
| Previous by Thread: | RE: Group Policy: multiple password policies in the same domain?, Derick Anderson |
| Next by Thread: | RE: Group Policy: multiple password policies in the same domain?, Kurt Dillard |
| Indexes: | [Date] [Thread] [Top] [All Lists] |