Link to home
Start Free TrialLog in
Avatar of pgp4privacy
pgp4privacy

asked on

GPO setting not being enforced

I have a Windows 2003 Server Active Directory domain.  I have two group policies which I apply domain wide.

I had initially enabled password expiry, but them shortly after removed it.

For some reason, now, users are still getting prompted that their password is to expire even though no GPO has this feature enabled.

I have run gpupdate /force on a machine and also used SpecOps AD extension to run gpupdate /force on all machines in the domain.

Any suggestions would be greatly appreciated
Avatar of Zenith63
Zenith63

The first thing to note, which you may already know, is that an Active Directory domain can only have one password policy and it applies to all users.  You can't stop it applying to certain users or only apply it to certain users.  It also must be defined in a GPO linked to the root of the domain. (see http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/directory/activedirectory/stepbystep/strngpw.mspx#EMD for more info).

Try running 'gpresult /v' from one of the PCs.  This will show you the GP settings that are in force on that PC which might help identify where the password policy is coming from.
ASKER CERTIFIED SOLUTION
Avatar of Barca
Barca
Flag of Hong Kong image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial