Password Policy on SBS 2003 R2: Advanced Management

I'm running a small business server 2003.

From the Server Management, I go to Advanced Management -> Group Policy Management -> Domains -> domain.local -> Small Business Server Domain Password Policy.

The current policy sets the Maximum Password Age to 14 days, and the minimum length is 8 characters.

I want 45 days and 15 characters as the minimum. So I right click on the policy, and go to edit. It brings up the Group Policy Object Editor.

I go to Computer Configuration -> Windows Settings -> Security Settings -> Account Policies -. Password Policy.

I edit Maximum password age to 45 days, and put 14 characters as minimum length (It will not let me select 15).

Now, here is the thing: Above the "Small Business Server Domain Password Policy" I have a "Default Domain Policy" that is set to 42 days for max age and 7 characters for minimum length.

There is a conflict here... why is it that when I open these to edit, GPO Editor is opened?

How do I trace these conflicting policies down and get the result that I want?!

mnbookmanAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

ormerodrutterCommented:
Anything you manually entered surecede the default policy.

For example, if you don't enter anything the Default policy will kick in. But if you have a customer policy it will override the existing Default policy.
0
mnbookmanAuthor Commented:
I took over for someone else and... a year later I'm still trying to figure things out. :)

How do I trace policies to see which ones are in effect?
0
DrDave242Commented:
First, the easy question: the GPO Editor gets opened when you edit a GPO because...that's the tool that is used to edit GPOs.  :)

Now the rest.  You can see which policy takes precedence in the Group Policy Management Console.  In this case, both policies should be applied at the domain level (since that's the only place you can specify a password policy in 2003), so click on the domain name in the left pane of the console.  Then click on the Group Policy Inheritance tab in the right pane.  Policies higher in the list take precedence over those lower in the list.  (There are exceptions to this rule, such as when a policy is given the Enforced/No Override setting, but that's not likely true in your case.)
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
mnbookmanAuthor Commented:
Thanks DrDave242, with your help, I may have this licked... Is there any way to check account statistics for individual users - for example, how many days are left before their password change?

I was completely misunderstanding how policies are laid out. Under Domains ->domain.local, I thought each policy was a SUMMARY, and wasn't understanding that when I right clicked on one and selected 'Edit' that I was only editing THAT policy. I thought each edit was taking me to the same place.

Now I understand there is a hierarchy.
0
DrDave242Commented:
The Account Lockout and Management Tools should give you the information you need:

http://www.microsoft.com/downloads/details.aspx?FamilyId=7AF2E69C-91F3-4E63-8629-B999ADDE0B9E&displaylang=en

This article gives some information on using the tools:

http://www.windowsecurity.com/articles/Implementing-Troubleshooting-Account-Lockout.html
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
SBS

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.