Advertisement

04.23.2008 at 08:23AM PDT, ID: 23346953
[x]
Attachment Details

GP Default domain policy not applying to users

Asked by BerryGardens in Active Directory, Windows 2003 Server, Microsoft Applications

Tags: , , ,

I have changed the default domain policy but it has not applied.

I have amended the default domain policy and enforced to authenticated users - when I test it still meets the old settings on some and changes on others but not applying. For example I can still change the password meeting the old requirements.

I have done rsop.msc and security settings reporting correctly (on some)

Attached is a client gpo.txt for example.

Old Policy:
2 passwords remembered
Max 120 days
Min 0 days
4 characters
complexity - disabled
disabled

New policy:
5 passwords remembered
Max 60 days
Min 0 days
6 Characters
complexity - Enabled
disabled

ANY HELP - 500 points - thanks

@@@@@@@@@@@@@@@@@@@@@@@@@@@GP RESULT@@@@@@@@@@

Microsoft (R) Windows (R) XP Operating System Group Policy Result tool v2.0
Copyright (C) Microsoft Corp. 1981-2001

Created On 23/04/2008 at 16:18:48



RSOP results for domain\user1 on LAPTOP1 : Logging Mode
-------------------------------------------------------------------

OS Type:                     Microsoft Windows XP Professional
OS Configuration:            Member Workstation
OS Version:                  5.1.2600
Domain Name:                 domain
Domain Type:                 Windows 2000
Site Name:                   sitename
Roaming Profile:            
Local Profile:               C:\Documents and Settings\user
Connected over a slow link?: No


COMPUTER SETTINGS
------------------
    CN=LTFOG-809,OU=Laptop,OU=Computers,OU=Five Oak Green,OU=Sites,OU=Berry Gardens,DC=kgfruits,DC=local
    Last time Group Policy was applied: 23/04/2008 at 15:49:23
    Group Policy was applied from:      kgfax.kgfruits.local
    Group Policy slow link threshold:   64 kbps

    Applied Group Policy Objects
    -----------------------------
        Default Domain Policy

    The following GPOs were not applied because they were filtered out
    -------------------------------------------------------------------
        Local Group Policy
            Filtering:  Not Applied (Empty)

    The computer is a part of the following security groups:
    --------------------------------------------------------
        BUILTIN\Administrators
        Everyone
        BUILTIN\Users
        NT AUTHORITY\NETWORK
        NT AUTHORITY\Authenticated Users
        LTFOG-809$
        Domain Computers
       
    Resultant Set Of Policies for Computer:
    ----------------------------------------

        Software Installations
        ----------------------
            N/A

        Startup Scripts
        ---------------
            N/A

        Shutdown Scripts
        ----------------
            N/A

        Account Policies
        ----------------
            GPO: Default Domain Policy
                Policy:            MinimumPasswordAge
                Computer Setting:  N/A

            GPO: Default Domain Policy
                Policy:            PasswordHistorySize
                Computer Setting:  2

            GPO: Default Domain Policy
                Policy:            LockoutDuration
                Computer Setting:  30

            GPO: Default Domain Policy
                Policy:            ResetLockoutCount
                Computer Setting:  30

            GPO: Default Domain Policy
                Policy:            MinimumPasswordLength
                Computer Setting:  4

            GPO: Default Domain Policy
                Policy:            LockoutBadCount
                Computer Setting:  5

            GPO: Default Domain Policy
                Policy:            MaximumPasswordAge
                Computer Setting:  120

        Audit Policy
        ------------
            N/A

        User Rights
        -----------
            N/A

        Security Options
        ----------------
            GPO: Default Domain Policy
                Policy:            RequireLogonToChangePassword
                Computer Setting:  Not Enabled

            GPO: Default Domain Policy
                Policy:            PasswordComplexity
                Computer Setting:  Not Enabled

            GPO: Default Domain Policy
                Policy:            ForceLogoffWhenHourExpire
                Computer Setting:  Enabled

            GPO: Default Domain Policy
                Policy:            ClearTextPassword
                Computer Setting:  Not Enabled

        Event Log Settings
        ------------------
            GPO: Default Domain Policy
                Policy:            RetentionDays
                Computer Setting:  0
                Log Name:          Application

            GPO: Default Domain Policy
                Policy:            RetentionDays
                Computer Setting:  0
                Log Name:          System

            GPO: Default Domain Policy
                Policy:            RetentionDays
                Computer Setting:  0
                Log Name:          Security

        Restricted Groups
        -----------------
            N/A

        System Services
        ---------------
            N/A

        Registry Settings
        -----------------
            N/A

        File System Settings
        --------------------
            N/A

        Public Key Policies
        -------------------
            N/A

        Administrative Templates
        ------------------------
            GPO: Default Domain Policy
                Setting: Software\Policies\Microsoft\Windows\System
                State:   disabled

            GPO: Default Domain Policy
                Setting: Software\Policies\Microsoft\Windows\System
                State:   Enabled

            GPO: Default Domain Policy
                Setting: Software\Policies\Microsoft\Windows\System
                State:   Enabled

            GPO: Default Domain Policy
                Setting: Software\Policies\Microsoft\Windows\System
                State:   Enabled

            GPO: Default Domain Policy
                Setting: Software\Microsoft\Windows\CurrentVersion\Policies\System
                State:   Enabled

            GPO: Default Domain Policy
                Setting: Software\Policies\Microsoft\Windows\System
                State:   Enabled

            GPO: Default Domain Policy
                Setting: Software\Policies\Microsoft\Windows NT\CurrentVersion\Winlogon
                State:   Enabled

            GPO: Default Domain Policy
                Setting: Software\Policies\Microsoft\Windows\System
                State:   Enabled

            GPO: Default Domain Policy
                Setting: Software\Microsoft\Windows\CurrentVersion\Policies\System
                State:   Enabled

            GPO: Default Domain Policy
                Setting: Software\Microsoft\Windows\CurrentVersion\Policies\System
                State:   Enabled

            GPO: Default Domain Policy
                Setting: Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
                State:   disabled

            GPO: Default Domain Policy
                Setting: Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
                State:   Enabled

            GPO: Default Domain Policy
                Setting: Software\Policies\Microsoft\Windows\System
                State:   Enabled

            GPO: Default Domain Policy
                Setting: Software\Policies\Microsoft\Windows\System
                State:   Enabled


USER SETTINGS
--------------
    CN=Lizzy Bowen,OU=Users,OU=Five Oak Green,OU=Sites,OU=Berry Gardens,DC=kgfruits,DC=local
    Last time Group Policy was applied: 23/04/2008 at 15:50:17
    Group Policy was applied from:      <domain>
    Group Policy slow link threshold:   500 kbps

    Applied Group Policy Objects
    -----------------------------
        UK Login Script

    The following GPOs were not applied because they were filtered out
    -------------------------------------------------------------------
        Default Domain Policy
            Filtering:  Disabled (GPO)

        Local Group Policy
            Filtering:  Not Applied (Empty)

    The user is a part of the following security groups:
    ----------------------------------------------------
        Domain Users
        Everyone
        SophosUser
        BUILTIN\Administrators
        BUILTIN\Users
        NT AUTHORITY\INTERACTIVE
        NT AUTHORITY\Authenticated Users
        LOCAL
        All Staff
       
       
    Resultant Set Of Policies for User:
    ------------------------------------

        Software Installations
        ----------------------
            N/A

        Public Key Policies
        -------------------
            N/A

        Administrative Templates
        ------------------------
            GPO: UK Login Script
                Setting: Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop
                State:   Enabled

        Folder Redirection
        ------------------
            N/A

        Internet Explorer Browser User Interface
        ----------------------------------------
            N/A

        Internet Explorer Connection
        ----------------------------
            N/A

        Internet Explorer URLs
        ----------------------
            N/A

        Internet Explorer Security
        --------------------------
            N/A

        Internet Explorer Programs
        --------------------------
            N/A
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@Start Free Trial
[+][-]04.23.2008 at 08:30AM PDT, ID: 21421789

Assisted solutions are selected by the member who asked the question as a comment that contributed to their question's solution.

Start your 7-day free trial to view this Assisted Solution or ask the Experts your question.

 
[+][-]04.23.2008 at 08:32AM PDT, ID: 21421814

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]04.23.2008 at 08:45AM PDT, ID: 21421973

Assisted solutions are selected by the member who asked the question as a comment that contributed to their question's solution.

Start your 7-day free trial to view this Assisted Solution or ask the Experts your question.

 
[+][-]04.23.2008 at 08:49AM PDT, ID: 21422031

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]04.23.2008 at 08:53AM PDT, ID: 21422076

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]04.23.2008 at 08:59AM PDT, ID: 21422143

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]04.23.2008 at 09:03AM PDT, ID: 21422191

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]04.23.2008 at 09:10AM PDT, ID: 21422268

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]04.23.2008 at 09:30AM PDT, ID: 21422523

View this solution now by starting your 7-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

 

About this solution

Zones: Active Directory, Windows 2003 Server, Microsoft Applications
Tags: Microsoft, Active Directory, 2003, Password Policy Domain
Sign Up Now!
Solution Provided By: l8night
Participating Experts: 3
Solution Grade: A
 
 
[+][-]04.23.2008 at 11:40AM PDT, ID: 21423871

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
 
Loading Advertisement...
20080716-EE-VQP-32 / EE_QW_2_20070628