Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: Group Policy: multiple password policies in the same domain? |
|---|---|
| Date: | Wed, 31 Aug 2005 15:23:47 -0400 |
Inline...
-----Original Message----- From: Beauford, Jason [mailto:jbeauford@EightInOnePet.com] Domain Wide Password policies cannot be blocked by OU Policies.
It's not a matter of blocking. It's a matter of where the accounts are actually stored. AD accounts are stored in the *domain*, so that is the only place where a password policy affects *domain* accounts. OUs are irrelevant in that scenario.
With that in mind you should look at creating an OU and setting up a GPO with Password Policies there rather than on the top level domain. Drop your service accounts into the OU and they will take on the the applied GPO.
No, they won't. Moving the service account from one OU to another has no affect. The account is still stored in AD and is still subject to the *domain* password policy. Creating *local* accounts on the computer(s) in question, then setting password policies on the OUs where the *computers* reside, would work. However, it wouldn't meet the requirements of the original poster.
Because you have no other password policy set on the top level domain name, your "other" users will be unaffected.
That is not the case. See above.
I believe that should do it. But then again. I haven't tested it or ever implemented it to confirm. Check it out.
I have tested and implemented this stuff eight ways to Sunday, but I encourage anybody who doesn't want to take my word for it to test for himself/herself. :-) Laura --------------------------------------------------------------------------- ---------------------------------------------------------------------------
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: Group Policy: multiple password policies in the same domain?, Laura A. Robinson |
|---|---|
| Next by Date: | RE: Group Policy: multiple password policies in the same domain?, Derick Anderson |
| Previous by Thread: | RE: Group Policy: multiple password policies in the same domain?, Laura A. Robinson |
| Next by Thread: | RE: Group Policy: multiple password policies in the same domain?, Derick Anderson |
| Indexes: | [Date] [Thread] [Top] [All Lists] |