Click here to get back home

How Policies Work

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
How Policies Work Kim 11-17-2006
`--> Re: How Policies Work Roger Abell [MV...11-18-2006
Posted by Kim on November 17, 2006, 2:43 pm
Please log in for more thread options
In the following situation which policy will win?

Enforce password history

Default Domain Policy Not defined
Default Domain Controller Policy Not defined
Local Domain Controller Policy 24 days

My problem is when a users profile is set to change at next logon (because I
don't want to know there password) if they select a password that was used in
the last 24 days it won't accept it. I would have thought that the default
domain policy or default domain controller policy would have taken precedence.

Any answers would be greatly appreciated.

Kim



Posted by Roger Abell [MVP] on November 18, 2006, 12:32 am
Please log in for more thread options
Not defined does not mean no policy, it just means that
there is no definition of the specific policy in that GPO.
Notice that many policies are tri-state, such as not defined,
enabled, disabled. A setting of not defined is a no-op and
has no effect.
Now, usually Account policies only have affect on domain
accounts when these are set in a GPO linked to the domain.
I have at times noticed it seems some are effective for domain
accounts when set in a GPO linked to the DC OU. Given the
possible GPOs that you have listed, either this "odd" behavior
(that is not supposed to happen) is operative here, or, more
likely, the shipped default or last set value at the domain level
is being used (i.e. the 24 in the DC OU linked GPO only appears
to be winning, but in fact, no GPO linked to the domain sets the
policy so the last set value is being effective).

> In the following situation which policy will win?
>
> Enforce password history
>
> Default Domain Policy Not defined
> Default Domain Controller Policy Not defined
> Local Domain Controller Policy 24 days
>
> My problem is when a users profile is set to change at next logon (because
> I
> don't want to know there password) if they select a password that was used
> in
> the last 24 days it won't accept it. I would have thought that the
> default
> domain policy or default domain controller policy would have taken
> precedence.
>
> Any answers would be greatly appreciated.
>
> Kim
>
>



Similar ThreadsPosted
how do I work out who/what enabled a service October 3, 2005, 10:48 pm
FileSystemAuditing doesn't work good October 17, 2006, 8:34 am
revoking ipsec certificate doesn't work September 15, 2005, 4:01 pm
How does runas with /netonly option work? February 8, 2006, 8:12 am
special permissions on folder don't work April 28, 2006, 1:54 am
STOP what you’re doing - It doesn’t work! LT69 July 28, 2006, 7:17 pm
Importing certificates does not work on Vista: February 5, 2008, 2:31 pm
Access Based Enumeration really doesn't work May 13, 2008, 11:13 am
Network drives show disconnected, sometimes, but still work? November 30, 2007, 8:31 pm
ASP.NET Performance Counters don't work monitoring several remote 2003 servers. February 1, 2007, 12:46 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap