Solved

need to set policy on account so it does not lock out........

Posted on 2006-11-15
7
322 Views
Last Modified: 2010-04-18
Ok im hoping someone can help with this one,
We currently are running a 2003 ad, with several sites managed by local it staff.
our default domain controller policy locks out user accounts after 3 invalid passwords to meet SOX requirements.
I current issue is that some of our sites have alot of usere that use the same account, to logon and do generic tasks. The account is locked down to be verry restricted on what the user can do.
But because so many people are using the one account, issues such as some one fat fingering the password or having the caps lock on causes the account to lock out after 3 invalid attempts thus locking out any one who uses the account.
I need a way set no lockout on this one account, but i dont see any options to do this in AD. Is there a way or is there some 3rd party software that would alow me to make this change so the user ID does not lock EVER?
Thanks
0
Comment
Question by:prelude812
  • 2
7 Comments
 
LVL 2

Expert Comment

by:sscuser
ID: 17949269
Probably the best solution is to create a seperate OU for those users, create a GP object that does not have lockouts, and apply it to that OU...

So, have the setting undefined on your default policy...create two OU's, one for normal users and one for the non-lockout users, and define the lockout within the OU specific GP's...or just remove the lockout policy altogether.
0
 
LVL 48

Expert Comment

by:Jay_Jay70
ID: 17951448
You can have only one password polic per domain. No work arounds (unless you go third party app) but as far as AD is concerned its one and thats it
0
 
LVL 51

Accepted Solution

by:
Netman66 earned 500 total points
ID: 17952086
The only way to do this without 3rd party applications (which I don't know of any off the top) is to put that user account in it's own domain.  By default, the Domain is a Security Boundary - which reinforces Jay's statement that you can only have one Account Policy in the domain that cannot be blocked or overridden.

Contrary to what others on this site have determined, it's not possible.  Placing policies on OUs only affects LOCAL logons to the workstation - NOT domain logons.

0
 
LVL 51

Expert Comment

by:Netman66
ID: 18385462
I think the answer was provided.
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Organizations create, modify, and maintain huge amounts of data to help their businesses earn money and generally function.  Typically every network user within an organization has a bit of disk space to store in process items and personal files.   …
by Batuhan Cetin In this article I will be guiding through the process of removing a failed DC metadata from Active Directory (hereafter, AD) using the ntdsutil tool in a Windows Server 2003 environment. These steps are not necessary in a Win…
This Micro Tutorial will give you a basic overview how to record your screen with Microsoft Expression Encoder. This program is still free and open for the public to download. This will be demonstrated using Microsoft Expression Encoder 4.
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…

910 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

15 Experts available now in Live!

Get 1:1 Help Now