Link to home
Start Free TrialLog in
Avatar of jasonbournecia
jasonbourneciaFlag for United Kingdom of Great Britain and Northern Ireland

asked on

Enforcing password policy the sequel

Hi,
I'm trying to enforce a password policy at work, but it is not working.
I set it first in default domain policy, ran gpupdate, even rebooted, nothing.
Outside IT person came in and said do it through Domain security Policy, did this, the same; nothing. That only shows it as set under default domain policy.
Times moved on now, the above was a month ago. Let me tell you what happened today.

I set the password policy in both 'default domain policy' and 'Small Business Server Domain Password Policy'
Ran gpupdate, Nothing happened. However a few miinutes I was tidying up group membership under users and I removed the 'Mobile User' group from our remote offices; I dont believe they needed it. Suddenly I get calls from them saying they're needing to change passwords. They changed their passwords and all is well including mapped drives. Great so far, but it is not happening for the domain users at head office where the SBS 2003 server is. BTW, the remote offices are not in the domain.
Now, the other intersting bit, someone at head office rebooted their machine and were asked to change their password.
This did not happen for other people when they rebooted. I went into that person's account and noticed she had 'Internet Users' in her account. I have removed it for now.
Have you any idea why the password policy is not working for all the other members of the domain and why, if it is not a coincidence, has it worked for members who were removed from 'Mobile Users' and the one person who had 'internet Users' in her members of list?
Any help much appreciated.
John
Cheers
John
Avatar of Toni Uranjek
Toni Uranjek
Flag of Slovenia image

Hi!

Cases when password policy defined at domain level does not apply to Domain Controllers OU:
1. If you enable "Block Policy Inheritance" on Domain Controllers OU.
2. Another posibillity: you have Security Filtering for GPO enabled.

You should go to command prompt on DC, and run "gpresult /v > gpo.txt" and then check gpo.txt file. There will be section which GPOs apply and which don't and reason why they don't.
You can post that particular part of the file here.

HTH

Toni
Avatar of jasonbournecia

ASKER

Hi Toniur,

I've attached the whole gpo.txt. Can you see anything untoward?

By the way, one other person has had a password change request but none others; there are at least 15 other people in today. Her account does not appear to be any different.
Cheers
John

Microsoft (R) Windows (R) Operating System Group Policy Result tool v2.0
Copyright (C) Microsoft Corp. 1981-2001
 
Created On 14/03/2008 at 16:10:24
 
 
RSOP data for bob\administrator on bobbo : Logging Mode
-----------------------------------------------------------
 
OS Type:                     Microsoft(R) Windows(R) Server 2003 for Small Business Server
OS Configuration:            Primary Domain Controller
OS Version:                  5.2.3790
Terminal Server Mode:        Remote Administration
Site Name:                   Default-First-Site-Name
Roaming Profile:             
Local Profile:               C:\Documents and Settings\Administrator
Connected over a slow link?: No
 
 
COMPUTER SETTINGS
------------------
    CN=bobbo,OU=Domain Controllers,DC=bob,DC=local
    Last time Group Policy was applied: 14/03/2008 at 16:06:07
    Group Policy was applied from:      bobbo.BOB.local
    Group Policy slow link threshold:   500 kbps
    Domain Name:                        BOB
    Domain Type:                        Windows 2000
 
    Applied Group Policy Objects
    -----------------------------
        Small Business Server Auditing Policy
        Default Domain Controllers Policy
        Small Business Server Client Computer
        Small Business Server Remote Assistance Policy
        Small Business Server Lockout Policy
        Small Business Server Domain Password Policy
        Default Domain Policy
        Local Group Policy
 
    The following GPOs were not applied because they were filtered out
    -------------------------------------------------------------------
        Small Business Server Internet Connection Firewall
            Filtering:  Denied (WMI Filter)
            WMI Filter: PreSP2
 
        Small Business Server Windows Firewall
            Filtering:  Denied (WMI Filter)
            WMI Filter: PostSP2
 
        Small Business Server - Windows Vista policy
            Filtering:  Denied (WMI Filter)
            WMI Filter: Vista
 
    The computer is a part of the following security groups
    -------------------------------------------------------
        BUILTIN\Administrators
        Everyone
        BUILTIN\Users
        BUILTIN\Pre-Windows 2000 Compatible Access
        Windows Authorization Access Group
        NT AUTHORITY\NETWORK
        NT AUTHORITY\Authenticated Users
        This Organization
        BOBBO$
        Domain Controllers
        Exchange Domain Servers
        NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS
        Exchange Enterprise Servers
        RAS and IAS Servers
        
    Resultant Set Of Policies for Computer
    ---------------------------------------
 
        Software Installations
        ----------------------
            N/A
 
        Startup Scripts
        ---------------
            N/A
 
        Shutdown Scripts
        ----------------
            N/A
 
        Account Policies
        ----------------
            GPO: Default Domain Policy
                Policy:            MaxServiceAge
                Computer Setting:  600
 
            GPO: Default Domain Policy
                Policy:            MaxTicketAge
                Computer Setting:  10
 
            GPO: Small Business Server Domain Password Policy
                Policy:            MinimumPasswordAge
                Computer Setting:  30
 
            GPO: Small Business Server Domain Password Policy
                Policy:            PasswordHistorySize
                Computer Setting:  24
 
            GPO: Small Business Server Lockout Policy
                Policy:            LockoutDuration
                Computer Setting:  10
 
            GPO: Small Business Server Lockout Policy
                Policy:            ResetLockoutCount
                Computer Setting:  10
 
            GPO: Default Domain Policy
                Policy:            MaxClockSkew
                Computer Setting:  5
 
            GPO: Small Business Server Domain Password Policy
                Policy:            MinimumPasswordLength
                Computer Setting:  7
 
            GPO: Small Business Server Lockout Policy
                Policy:            LockoutBadCount
                Computer Setting:  50
 
            GPO: Small Business Server Domain Password Policy
                Policy:            MaximumPasswordAge
                Computer Setting:  100
 
            GPO: Default Domain Policy
                Policy:            MaxRenewAge
                Computer Setting:  7
 
        Audit Policy
        ------------
            GPO: Default Domain Controllers Policy
                Policy:            AuditPolicyChange
                Computer Setting:  Success
 
            GPO: Default Domain Controllers Policy
                Policy:            AuditPrivilegeUse
                Computer Setting:  No Auditing
 
            GPO: Small Business Server Auditing Policy
                Policy:            AuditDSAccess
                Computer Setting:  No Auditing
 
            GPO: Default Domain Controllers Policy
                Policy:            AuditAccountLogon
                Computer Setting:  Success
 
            GPO: Default Domain Controllers Policy
                Policy:            AuditObjectAccess
                Computer Setting:  No Auditing
 
            GPO: Default Domain Controllers Policy
                Policy:            AuditAccountManage
                Computer Setting:  Success
 
            GPO: Small Business Server Auditing Policy
                Policy:            AuditLogonEvents
                Computer Setting:  Success, Failure
 
            GPO: Default Domain Controllers Policy
                Policy:            AuditProcessTracking
                Computer Setting:  No Auditing
 
            GPO: Default Domain Controllers Policy
                Policy:            AuditSystemEvents
                Computer Setting:  Success
 
        User Rights
        -----------
            GPO: Default Domain Controllers Policy
                Policy:            MachineAccountPrivilege
                Computer Setting:  Authenticated Users
                                   
            GPO: Default Domain Controllers Policy
                Policy:            DenyNetworkLogonRight
                Computer Setting:  BOB\SUPPORT_388945a0
                                   
            GPO: Default Domain Controllers Policy
                Policy:            RestorePrivilege
                Computer Setting:  Administrators
                                   Backup Operators
                                   Server Operators
                                   
            GPO: Default Domain Controllers Policy
                Policy:            TcbPrivilege
                Computer Setting:  BOB\Administrator
                                   
            GPO: Default Domain Controllers Policy
                Policy:            SystemProfilePrivilege
                Computer Setting:  Administrators
                                   
            GPO: Default Domain Controllers Policy
                Policy:            DenyServiceLogonRight
                Computer Setting:  N/A
 
            GPO: Default Domain Controllers Policy
                Policy:            ServiceLogonRight
                Computer Setting:  BOB\SQLServer2005MSSQLUser$BOBBO$MICROSOFT##SSEE
                                   NETWORK SERVICE
                                   BOB\Administrator
                                   BOB\SophosSAUBOBBO0
                                   
            GPO: Default Domain Controllers Policy
                Policy:            UndockPrivilege
                Computer Setting:  Administrators
                                   
            GPO: Default Domain Controllers Policy
                Policy:            CreatePermanentPrivilege
                Computer Setting:  N/A
 
            GPO: Default Domain Controllers Policy
                Policy:            AuditPrivilege
                Computer Setting:  LOCAL SERVICE
                                   NETWORK SERVICE
                                   
            GPO: Default Domain Controllers Policy
                Policy:            TakeOwnershipPrivilege
                Computer Setting:  Administrators
                                   
            GPO: Default Domain Controllers Policy
                Policy:            CreatePagefilePrivilege
                Computer Setting:  Administrators
                                   
            GPO: Default Domain Controllers Policy
                Policy:            EnableDelegationPrivilege
                Computer Setting:  Administrators
                                   
            GPO: Default Domain Controllers Policy
                Policy:            DebugPrivilege
                Computer Setting:  Administrators
                                   
            GPO: Default Domain Controllers Policy
                Policy:            SystemTimePrivilege
                Computer Setting:  Administrators
                                   Server Operators
                                   LOCAL SERVICE
                                   
            GPO: Default Domain Controllers Policy
                Policy:            DenyBatchLogonRight
                Computer Setting:  N/A
 
            GPO: Default Domain Controllers Policy
                Policy:            BackupPrivilege
                Computer Setting:  Administrators
                                   Backup Operators
                                   Server Operators
                                   
            GPO: Default Domain Controllers Policy
                Policy:            CreateTokenPrivilege
                Computer Setting:  BOB\Administrator
                                   
            GPO: Default Domain Controllers Policy
                Policy:            ChangeNotifyPrivilege
                Computer Setting:  Everyone
                                   Administrators
                                   Authenticated Users
                                   Pre-Windows 2000 Compatible Access
                                   BOB\Administrator
                                   BOB\SQLServer2005MSSQLUser$BOBBO$MICROSOFT##SSEE
                                   
            GPO: Default Domain Controllers Policy
                Policy:            SyncAgentPrivilege
                Computer Setting:  N/A
 
            GPO: Default Domain Controllers Policy
                Policy:            ProfileSingleProcessPrivilege
                Computer Setting:  Administrators
                                   
            GPO: Default Domain Controllers Policy
                Policy:            LoadDriverPrivilege
                Computer Setting:  Administrators
                                   Print Operators
                                   
            GPO: Default Domain Controllers Policy
                Policy:            InteractiveLogonRight
                Computer Setting:  BOB\IUSR_BOBBO
                                   Administrators
                                   Backup Operators
                                   Account Operators
                                   Server Operators
                                   Print Operators
                                   
            GPO: Default Domain Controllers Policy
                Policy:            RemoteShutdownPrivilege
                Computer Setting:  Administrators
                                   Server Operators
                                   
            GPO: Default Domain Controllers Policy
                Policy:            IncreaseBasePriorityPrivilege
                Computer Setting:  Administrators
                                   
            GPO: Default Domain Controllers Policy
                Policy:            NetworkLogonRight
                Computer Setting:  Everyone
                                   BOB\IUSR_BOBBO
                                   BOB\IWAM_BOBBO
                                   Administrators
                                   Authenticated Users
                                   ENTERPRISE DOMAIN CONTROLLERS
                                   Pre-Windows 2000 Compatible Access
                                   
            GPO: Default Domain Controllers Policy
                Policy:            LockMemoryPrivilege
                Computer Setting:  N/A
 
            GPO: Default Domain Controllers Policy
                Policy:            ShutdownPrivilege
                Computer Setting:  Administrators
                                   Backup Operators
                                   Server Operators
                                   Print Operators
                                   
            GPO: Default Domain Controllers Policy
                Policy:            SecurityPrivilege
                Computer Setting:  BOB\Exchange Enterprise Servers
                                   Administrators
                                   
            GPO: Default Domain Controllers Policy
                Policy:            AssignPrimaryTokenPrivilege
                Computer Setting:  BOB\SQLServer2005MSSQLUser$BOBBO$MICROSOFT##SSEE
                                   LOCAL SERVICE
                                   NETWORK SERVICE
                                   BOB\IWAM_BOBBO
                                   BOB\Administrator
                                   
            GPO: Default Domain Controllers Policy
                Policy:            SystemEnvironmentPrivilege
                Computer Setting:  Administrators
                                   
            GPO: Default Domain Controllers Policy
                Policy:            IncreaseQuotaPrivilege
                Computer Setting:  BOB\Administrator
                                   LOCAL SERVICE
                                   NETWORK SERVICE
                                   BOB\IWAM_BOBBO
                                   Administrators
                                   BOB\SQLServer2005MSSQLUser$BOBBO$MICROSOFT##SSEE
                                   
            GPO: Default Domain Controllers Policy
                Policy:            BatchLogonRight
                Computer Setting:  BOB\SQLServer2005MSSQLUser$BOBBO$MICROSOFT##SSEE
                                   BOB\EMLibUser1
                                   BUILTIN
                                   LOCAL SERVICE
                                   BOB\IUSR_BOBBO
                                   BOB\IWAM_BOBBO
                                   BOB\IIS_WPG
                                   BOB\SUPPORT_388945a0
                                   BOB\Administrator
                                   BOB\SQLDebugger
                                   BOB\SophosPMBOBBO0
                                   
            GPO: Default Domain Controllers Policy
                Policy:            DenyInteractiveLogonRight
                Computer Setting:  BOB\SBS Remote Operators
                                   BOB\SUPPORT_388945a0
                                   BOB\SBS STS Worker
                                   BOB\SQLDebugger
                                   BOB\SophosSAUBOBBO0
                                   
        Security Options
        ----------------
            GPO: Default Domain Policy
                Policy:            TicketValidateClient
                Computer Setting:  Enabled
 
            GPO: Default Domain Policy
                Policy:            RequireLogonToChangePassword
                Computer Setting:  Not Enabled
 
            GPO: Small Business Server Domain Password Policy
                Policy:            PasswordComplexity
                Computer Setting:  Enabled
 
            GPO: Default Domain Policy
                Policy:            ForceLogoffWhenHourExpire
                Computer Setting:  Not Enabled
 
            GPO: Small Business Server Domain Password Policy
                Policy:            ClearTextPassword
                Computer Setting:  Not Enabled
 
            GPO: Default Domain Controllers Policy
                Policy:            Microsoft network server: Digitally sign communications (if client agrees)
                ValueName:         MACHINE\System\CurrentControlSet\Services\LanManServer\Parameters\EnableSecuritySignature
                Computer Setting:  0
 
            GPO: Default Domain Controllers Policy
                Policy:            Network security: LAN Manager authentication level
                ValueName:         MACHINE\System\CurrentControlSet\Control\Lsa\LmCompatibilityLevel
                Computer Setting:  2
 
            GPO: Default Domain Controllers Policy
                Policy:            Microsoft network client: Digitally sign communications (if server agrees)
                ValueName:         MACHINE\System\CurrentControlSet\Services\LanmanWorkstation\Parameters\EnableSecuritySignature
                Computer Setting:  0
 
            GPO: Default Domain Controllers Policy
                Policy:            Microsoft network client: Digitally sign communications (always)
                ValueName:         MACHINE\System\CurrentControlSet\Services\LanmanWorkstation\Parameters\RequireSecuritySignature
                Computer Setting:  0
 
            GPO: Default Domain Controllers Policy
                Policy:            Domain controller: LDAP server signing requirements
                ValueName:         MACHINE\System\CurrentControlSet\Services\NTDS\Parameters\LDAPServerIntegrity
                Computer Setting:  1
 
            GPO: Default Domain Controllers Policy
                Policy:            Domain member: Digitally encrypt or sign secure channel data (always)
                ValueName:         MACHINE\System\CurrentControlSet\Services\Netlogon\Parameters\RequireSignOrSeal
                Computer Setting:  1
 
            GPO: Default Domain Controllers Policy
                Policy:            Microsoft network server: Digitally sign communications (always)
                ValueName:         MACHINE\System\CurrentControlSet\Services\LanManServer\Parameters\RequireSecuritySignature
                Computer Setting:  0
 
        Event Log Settings
        ------------------
            N/A
 
        Restricted Groups
        -----------------
            N/A
 
        System Services
        ---------------
            N/A
 
        Registry Settings
        -----------------
            N/A
 
        File System Settings
        --------------------
            N/A
 
        Public Key Policies
        -------------------
            N/A
 
        Administrative Templates
        ------------------------
            GPO: Default Domain Controllers Policy
                KeyName:     Software\Policies\Microsoft\Windows\WindowsUpdate\AU\AUOptions
                Value:       3, 0, 0, 0
                State:       Enabled
 
            GPO: Default Domain Controllers Policy
                KeyName:     Software\Policies\Microsoft\Windows\WindowsUpdate\AU\ScheduledInstallDay
                Value:       0, 0, 0, 0
                State:       Enabled
 
            GPO: Default Domain Policy
                KeyName:     Software\Policies\Microsoft\Windows\WindowsUpdate\WUServer
                State:       disabled
 
            GPO: Small Business Server Remote Assistance Policy
                KeyName:     software\policies\microsoft\windows NT\Terminal Services\fAllowUnsolicitedFullControl
                Value:       1, 0, 0, 0
                State:       Enabled
 
            GPO: Small Business Server Client Computer
                KeyName:     software\policies\microsoft\windows\network connections\NC_ShowSharedAccessUI
                Value:       0, 0, 0, 0
                State:       Enabled
 
            GPO: Default Domain Policy
                KeyName:     Software\Policies\Microsoft\Windows\WindowsUpdate\AU\DetectionFrequencyEnabled
                Value:       1, 0, 0, 0
                State:       Enabled
 
            GPO: Default Domain Controllers Policy
                KeyName:     Software\Policies\Microsoft\Windows\WindowsUpdate\AU\NoAUShutdownOption
                Value:       0, 0, 0, 0
                State:       Enabled
 
            GPO: Default Domain Policy
                KeyName:     Software\Policies\Microsoft\Windows\WindowsUpdate\WUStatusServer
                State:       disabled
 
            GPO: Small Business Server Remote Assistance Policy
                KeyName:     software\policies\microsoft\windows NT\Terminal Services\RAUnsolicit\BOB\Domain Admins
                Value:       69, 0, 89, 0, 67, 0, 92, 0, 68, 0, 111, 0, 109, 0, 97, 0, 105, 0, 110, 0, 32, 0, 65, 0, 100, 0, 109, 0, 105, 0, 110, 0, 115, 0, 0, 0
                State:       Enabled
 
            GPO: Default Domain Controllers Policy
                KeyName:     Software\Policies\Microsoft\Windows\WindowsUpdate\AU\NoAutoUpdate
                Value:       0, 0, 0, 0
                State:       Enabled
 
            GPO: Default Domain Policy
                KeyName:     Software\Policies\Microsoft\Windows\WindowsUpdate\AU\RebootRelaunchTimeoutEnabled
                Value:       1, 0, 0, 0
                State:       Enabled
 
            GPO: Default Domain Policy
                KeyName:     Software\Policies\Microsoft\Windows\WindowsUpdate\AU\RescheduleWaitTimeEnabled
                Value:       1, 0, 0, 0
                State:       Enabled
 
            GPO: Default Domain Policy
                KeyName:     Software\Policies\Microsoft\Windows\WindowsUpdate\AU\RescheduleWaitTime
                Value:       5, 0, 0, 0
                State:       Enabled
 
            GPO: Default Domain Controllers Policy
                KeyName:     Software\Policies\Microsoft\Windows\WindowsUpdate\AU\NoAutoRebootWithLoggedOnUsers
                Value:       1, 0, 0, 0
                State:       Enabled
 
            GPO: Small Business Server Client Computer
                KeyName:     software\microsoft\windows\currentversion\policies\explorer\NoWelcomeScreen
                Value:       1, 0, 0, 0
                State:       Enabled
 
            GPO: Small Business Server Client Computer
                KeyName:     software\microsoft\windows nt\currentversion\winlogon\SyncForegroundPolicy
                Value:       1, 0, 0, 0
                State:       Enabled
 
            GPO: Small Business Server Client Computer
                KeyName:     software\policies\microsoft\windows\network connections\NC_AllowNetBridge_NLA
                Value:       0, 0, 0, 0
                State:       Enabled
 
            GPO: Small Business Server Remote Assistance Policy
                KeyName:     software\policies\microsoft\windows NT\Terminal Services\fAllowUnsolicited
                Value:       1, 0, 0, 0
                State:       Enabled
 
            GPO: Default Domain Policy
                KeyName:     Software\Policies\Microsoft\Windows\WindowsUpdate\AU\DetectionFrequency
                Value:       22, 0, 0, 0
                State:       Enabled
 
            GPO: Default Domain Controllers Policy
                KeyName:     Software\Policies\Microsoft\Windows\WindowsUpdate\AU\AutoInstallMinorUpdates
                Value:       0, 0, 0, 0
                State:       Enabled
 
            GPO: Default Domain Policy
                KeyName:     Software\Policies\Microsoft\Windows\WindowsUpdate\AU\UseWUServer
                Value:       0, 0, 0, 0
                State:       Enabled
 
            GPO: Default Domain Policy
                KeyName:     Software\Policies\Microsoft\Windows\WindowsUpdate\AU\RebootRelaunchTimeout
                Value:       240, 0, 0, 0
                State:       Enabled
 
            GPO: Default Domain Controllers Policy
                KeyName:     Software\Policies\Microsoft\Windows\WindowsUpdate\AU\ScheduledInstallTime
                Value:       13, 0, 0, 0
                State:       Enabled
 
 
USER SETTINGS
--------------
    CN=Administrator,CN=Users,DC=BOB,DC=local
    Last time Group Policy was applied: 14/03/2008 at 16:09:41
    Group Policy was applied from:      bobbo.BOB.local
    Group Policy slow link threshold:   500 kbps
    Domain Name:                        BOB
    Domain Type:                        Windows 2000
    
    Applied Group Policy Objects
    -----------------------------
        Default Domain Policy
 
    The following GPOs were not applied because they were filtered out
    -------------------------------------------------------------------
        Small Business Server Internet Connection Firewall
            Filtering:  Denied (WMI Filter)
            WMI Filter: PreSP2
 
        Small Business Server Client Computer
            Filtering:  Not Applied (Empty)
 
        Small Business Server Windows Firewall
            Filtering:  Denied (WMI Filter)
            WMI Filter: PostSP2
 
        Small Business Server Domain Password Policy
            Filtering:  Not Applied (Empty)
 
        Small Business Server - Windows Vista policy
            Filtering:  Denied (WMI Filter)
            WMI Filter: Vista
 
        Local Group Policy
            Filtering:  Not Applied (Empty)
 
        Small Business Server Lockout Policy
            Filtering:  Disabled (GPO)
 
        Small Business Server Remote Assistance Policy
            Filtering:  Disabled (GPO)
 
    The user is a part of the following security groups
    ---------------------------------------------------
        Domain Users
        Everyone
        BUILTIN\Administrators
        BUILTIN\Users
        REMOTE INTERACTIVE LOGON
        NT AUTHORITY\INTERACTIVE
        NT AUTHORITY\Authenticated Users
        This Organization
        LOCAL
        Group Policy Creator Owners
        Accounts
        Domain Admins
        PMX_ADMIN
        SBS Internet Users
        Schema Admins
        SBS Mobile Users
        Enterprise Admins
        SBS Report Users
        Marketing
        Sophos Console Administrators
        Sophos DB Users
        Sophos DB Admins
        Offer Remote Assistance Helpers
        EMLibrary Users
        SophosAdministrator
        
    The user has the following security privileges
    ----------------------------------------------
 
        Bypass traverse checking
        Manage auditing and security log
        Back up files and directories
        Restore files and directories
        Change the system time
        Shut down the system
        Force shutdown from a remote system
        Take ownership of files or other objects
        Debug programs
        Modify firmware environment values
        Profile system performance
        Profile single process
        Increase scheduling priority
        Load and unload device drivers
        Create a pagefile
        Adjust memory quotas for a process
        Remove computer from docking station
        Perform volume maintenance tasks
        Impersonate a client after authentication
        Create global objects
        Enable computer and user accounts to be trusted for delegation
        Add workstations to domain
 
    Resultant Set Of Policies for User
    -----------------------------------
 
        Software Installations
        ----------------------
            N/A
 
        Logon Scripts
        -------------
            N/A
 
        Logoff Scripts
        --------------
            N/A
 
        Public Key Policies
        -------------------
            N/A
 
        Administrative Templates
        ------------------------
            N/A
 
        Folder Redirection
        ------------------
            N/A
 
        Internet Explorer Browser User Interface
        ----------------------------------------
            N/A
 
        Internet Explorer Connection
        ----------------------------
            N/A
 
        Internet Explorer URLs
        ----------------------
            N/A
 
        Internet Explorer Security
        --------------------------
            N/A
 
        Internet Explorer Programs
        --------------------------
            N/A

Open in new window

Hi Toni,
What in heavens name is going on!!!???
On Friday another person was asked to change their password, not the other 16 people who were in.
Today, Monday, another two people had a password change request.!
How can a password policy propogate so slowly? This is really worrying me now.
Any help
John
ASKER CERTIFIED SOLUTION
Avatar of Toni Uranjek
Toni Uranjek
Flag of Slovenia image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Thanks Toni,
I still can't believe how much there is behind the scenes with servers.
I have 4 years of hardware support and 2 years network support, albeit mostly end user support; but the buck stops with me!
I have an outside company for emergencies, but I would like to reach the stage where I'm self sufficient; still a little scared at present.
Your knowledge and input has helped and I really appreciate it.
Cheers
John
John, nobody is self sufficient when it comes to IT.

Return to EE for advice is all I can advise. ;)

Regards,

Toni