Solved

need to set policy on account so it does not lock out........

Posted on 2006-11-15
7
341 Views
Last Modified: 2010-04-18
Ok im hoping someone can help with this one,
We currently are running a 2003 ad, with several sites managed by local it staff.
our default domain controller policy locks out user accounts after 3 invalid passwords to meet SOX requirements.
I current issue is that some of our sites have alot of usere that use the same account, to logon and do generic tasks. The account is locked down to be verry restricted on what the user can do.
But because so many people are using the one account, issues such as some one fat fingering the password or having the caps lock on causes the account to lock out after 3 invalid attempts thus locking out any one who uses the account.
I need a way set no lockout on this one account, but i dont see any options to do this in AD. Is there a way or is there some 3rd party software that would alow me to make this change so the user ID does not lock EVER?
Thanks
0
Comment
Question by:prelude812
  • 2
7 Comments
 
LVL 2

Expert Comment

by:sscuser
ID: 17949269
Probably the best solution is to create a seperate OU for those users, create a GP object that does not have lockouts, and apply it to that OU...

So, have the setting undefined on your default policy...create two OU's, one for normal users and one for the non-lockout users, and define the lockout within the OU specific GP's...or just remove the lockout policy altogether.
0
 
LVL 48

Expert Comment

by:Jay_Jay70
ID: 17951448
You can have only one password polic per domain. No work arounds (unless you go third party app) but as far as AD is concerned its one and thats it
0
 
LVL 51

Accepted Solution

by:
Netman66 earned 500 total points
ID: 17952086
The only way to do this without 3rd party applications (which I don't know of any off the top) is to put that user account in it's own domain.  By default, the Domain is a Security Boundary - which reinforces Jay's statement that you can only have one Account Policy in the domain that cannot be blocked or overridden.

Contrary to what others on this site have determined, it's not possible.  Placing policies on OUs only affects LOCAL logons to the workstation - NOT domain logons.

0
 
LVL 51

Expert Comment

by:Netman66
ID: 18385462
I think the answer was provided.
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

The HP utility "HP Lights-Out Online Configuration Utility for Windows Server 2003/2008" could be of great use when it comes to remotely configure a HP servers ILO WITHOUT rebooting the server. We would only need to create and run scripts using thi…
Numerous times I have been asked this questions that what is it that makes my machine log on so slow, there have been cases where computers took 23 minute exactly after taking password and getting to the desktop. Interesting thing was the fact th…
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …
Established in 1997, Technology Architects has become one of the most reputable technology solutions companies in the country. TA have been providing businesses with cost effective state-of-the-art solutions and unparalleled service that is designed…

856 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question