Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Password Policy question

Status
Not open for further replies.

adfreek

IS-IT--Management
Jul 22, 2003
227
US
Hello,

We're trying to clarify an issue. We would like to implement a password policy (aging, resets, etc) in our domain. We're a single W2K3 domain running AD. We would like to set up multiple OU's and implement seperate password policies. Is this possible? Some people have said that these settings can only be applied at the Default Domain Policy level?

Thanks
 
>We would like to set up multiple OU's and implement seperate password policies. Is this possible?

Yes, This is possible. Just like you said create different OU's

>Some people have said that these settings can only be applied at the Default Domain Policy level?

You can create multiple policies and apply them to whatever OU's you wish.
 
I'm pretty sure you will find that password policy at OU level will only affect local user accounts, the only policy that can affect domain user accounts is the domain policy.

You can set policy at OU level but test it and you will find that they have no affect.
 
It is only possible to have one password policy for DOMAIN users, and the policy must be set at the domain level.
 
As others have said - password policy only applies at a domain level. MS are apparently working on allowing OU level policies but I wouldn't hold my breath.

If you have different policies at the OU level they'll just be ignored (although I've read there's also a bug so you may get an OU password policy applied domain-wide if you're not careful but I can't see how this would happen...).
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top