Group Policy: User vs Computer Configuration

We want to implement the following Group Policy:
Computer Configuration > Windows Settings > Security Settings > Account Policies > Account Lockout Policy:
Account lockout duration:  0  (If a user gets locked out, he is not automatically unlocked. Only an Admin can unlock acct)
Account lockout threshold:  5 invalid logon attempts
Reset account lockout counter after 180 minutes

However, we don't want this to apply to any of our Admins.

This is currently the tree structure of our AD:
domain.local
     Staff OU
            Admins OU
            Sales OU
            Marketing OU
     Computers OU
            Sales Computers OU
            Marketing Computers OU
            Customer Services Computers OU

If this was a USER CONFIGURATION, I would just apply this GPO to the Staff OU, and then DISABLE this GPO for the Admins OU. But, since its a Computer Configuration, I'm not sure what's the best way to do this.
LVL 8
pzozulkaAsked:
Who is Participating?
 
oBdACommented:
Not possible in a W2k3 AD, unless with a third-party tool like from http://www.specopssoft.com/.
In a regular W2k3 AD, you can only have *one* password policy *per* *domain*, the password policy *has* to be linked to the domain root, and it *has* to apply to the DCs.
Only W2k8 supports "fine grained" password policies.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.