Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
?
Solved

default domain policy  ,password never expires , plan to implent maximum password age  42 days,problem  it include domain admins and sql accounts  not applied the this policy how can i come over this

Posted on 2008-10-23
5
Medium Priority
?
716 Views
Last Modified: 2011-10-19
I have default policy applied ,password never expires ,but now we are planning to implent maximum password age for 42 days,problem here is it also include domain admins and sql accounts which must not applied the this policy how can i come over this
0
Comment
Question by:girish_hn2003
  • 2
4 Comments
 
LVL 5

Accepted Solution

by:
balmasri earned 1000 total points
ID: 22784930
set the property of  these accounts to never expired individually.
Active directory users and computers console> User property>account
Untitled.jpg
0
 

Author Comment

by:girish_hn2003
ID: 22784976
thanks but is there any other option like create a new policy ,and enable option override and link it to default domain policy and apply to only to domain admin group in security filtering
0
 
LVL 71

Assisted Solution

by:Chris Dent
Chris Dent earned 1000 total points
ID: 22785186

Not with Windows 2003 I'm afraid.

If you were to upgrade your domain to 2008  (including the shift to 2008 Native Mode) you could use Fine Grained Password Policies. Without 2008 you're stuck with one password policy per domain, or third party software to look after it for you (there's nothing native).

Chris
0
 
LVL 5

Expert Comment

by:balmasri
ID: 22785263
In windows server 2003  domain level. Only one Password policy for a single domain. In windows 2008 , you have fine-grained   password policy you can apply.

http://technet.microsoft.com/en-us/library/cc770394.aspx
http://technet.microsoft.com/en-us/magazine/cc137749.aspx
http://www.experts-exchange.com/OS/Microsoft_Operating_Systems/Server/2003_Server/Q_23244174.html
0

Featured Post

Free Tool: IP Lookup

Get more info about an IP address or domain name, such as organization, abuse contacts and geolocation.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Microsoft Office 365 is a subscriptions based service which includes services like Exchange Online and Skype for business Online. These services integrate with Microsoft's online version of Active Directory called Azure Active Directory.
How to deal with a specific error when using the Enable-RemoteMailbox cmdlet to create a mailbox in the cloud-based service, for an existing user in an on-premises Active Directory.
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
Sometimes it takes a new vantage point, apart from our everyday security practices, to truly see our Active Directory (AD) vulnerabilities. We get used to implementing the same techniques and checking the same areas for a breach. This pattern can re…

580 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question