Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Focus-Microsoft
[Top] [All Lists]

RE: Group Policy: multiple password policies in the same domain?

Subject: RE: Group Policy: multiple password policies in the same domain?
Date: Wed, 31 Aug 2005 15:19:49 -0400
 Inline replies to a couple of different people.

You can only set password policies affecting domain 
accounts using the 
"default domain policy" GPO - ie. the GPO at the top of the AD tree 
for a particular domain.

Actually, that's not the case. You can only affect domain accounts at the
domain level, but you do NOT have to use the "Default Domain Policy" GPO.
You can create your own and it works. If you have multiple domain-level
policies that specify password settings, the last applied policy at the
domain level will "win". My other post answering the original question got
bounced, but I clarified some of this in it.

Does anyone know why the password policy is a computer and 
not a user-based setting?

Why would it be a computer setting? That would make no sense for all of the
users in the domain who are people rather than computers. Again, you can
only have a single password policy that affects accounts stored in AD for a
given domain. Because both users and computers are stored in AD, the
password policy applies to *any* account stored in AD. 

Laura


---------------------------------------------------------------------------
---------------------------------------------------------------------------

<Prev in Thread] Current Thread [Next in Thread>