Solved

Password Policy on SBS 2003 R2: Advanced Management

Posted on 2010-08-18
5
631 Views
Last Modified: 2012-05-10
I'm running a small business server 2003.

From the Server Management, I go to Advanced Management -> Group Policy Management -> Domains -> domain.local -> Small Business Server Domain Password Policy.

The current policy sets the Maximum Password Age to 14 days, and the minimum length is 8 characters.

I want 45 days and 15 characters as the minimum. So I right click on the policy, and go to edit. It brings up the Group Policy Object Editor.

I go to Computer Configuration -> Windows Settings -> Security Settings -> Account Policies -. Password Policy.

I edit Maximum password age to 45 days, and put 14 characters as minimum length (It will not let me select 15).

Now, here is the thing: Above the "Small Business Server Domain Password Policy" I have a "Default Domain Policy" that is set to 42 days for max age and 7 characters for minimum length.

There is a conflict here... why is it that when I open these to edit, GPO Editor is opened?

How do I trace these conflicting policies down and get the result that I want?!

0
Comment
Question by:mnbookman
  • 2
  • 2
5 Comments
 
LVL 23

Assisted Solution

by:ormerodrutter
ormerodrutter earned 100 total points
ID: 33466416
Anything you manually entered surecede the default policy.

For example, if you don't enter anything the Default policy will kick in. But if you have a customer policy it will override the existing Default policy.
0
 

Author Comment

by:mnbookman
ID: 33466623
I took over for someone else and... a year later I'm still trying to figure things out. :)

How do I trace policies to see which ones are in effect?
0
 
LVL 26

Accepted Solution

by:
DrDave242 earned 400 total points
ID: 33470478
First, the easy question: the GPO Editor gets opened when you edit a GPO because...that's the tool that is used to edit GPOs.  :)

Now the rest.  You can see which policy takes precedence in the Group Policy Management Console.  In this case, both policies should be applied at the domain level (since that's the only place you can specify a password policy in 2003), so click on the domain name in the left pane of the console.  Then click on the Group Policy Inheritance tab in the right pane.  Policies higher in the list take precedence over those lower in the list.  (There are exceptions to this rule, such as when a policy is given the Enforced/No Override setting, but that's not likely true in your case.)
0
 

Author Comment

by:mnbookman
ID: 33479997
Thanks DrDave242, with your help, I may have this licked... Is there any way to check account statistics for individual users - for example, how many days are left before their password change?

I was completely misunderstanding how policies are laid out. Under Domains ->domain.local, I thought each policy was a SUMMARY, and wasn't understanding that when I right clicked on one and selected 'Edit' that I was only editing THAT policy. I thought each edit was taking me to the same place.

Now I understand there is a hierarchy.
0
 
LVL 26

Assisted Solution

by:DrDave242
DrDave242 earned 400 total points
ID: 33480198
The Account Lockout and Management Tools should give you the information you need:

http://www.microsoft.com/downloads/details.aspx?FamilyId=7AF2E69C-91F3-4E63-8629-B999ADDE0B9E&displaylang=en

This article gives some information on using the tools:

http://www.windowsecurity.com/articles/Implementing-Troubleshooting-Account-Lockout.html
0

Featured Post

Zoho SalesIQ

Hassle-free live chat software re-imagined for business growth. 2 users, always free.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

The articles for turning off the Client firewall policy on the internet are for SBS 2008 and don't really help for SBS 2011. They actually moved the Client firewall policy. In 2011, the client firewall policy has moved to the SBS computers conta…
I work for a company that primarily works with small businesses as their outsourced IT vendor. As such the majority of these customers utilize some version of Small Business Server. Due to the economics of running a small business, many of these cus…
This Micro Tutorial will teach you how to censor certain areas of your screen. The example in this video will show a little boy's face being blurred. This will be demonstrated using Adobe Premiere Pro CS6.
Video by: Mark
This lesson goes over how to construct ordered and unordered lists and how to create hyperlinks.

862 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

23 Experts available now in Live!

Get 1:1 Help Now