Solved

Password Policy on SBS 2003 R2: Advanced Management

Posted on 2010-08-18
5
635 Views
Last Modified: 2012-05-10
I'm running a small business server 2003.

From the Server Management, I go to Advanced Management -> Group Policy Management -> Domains -> domain.local -> Small Business Server Domain Password Policy.

The current policy sets the Maximum Password Age to 14 days, and the minimum length is 8 characters.

I want 45 days and 15 characters as the minimum. So I right click on the policy, and go to edit. It brings up the Group Policy Object Editor.

I go to Computer Configuration -> Windows Settings -> Security Settings -> Account Policies -. Password Policy.

I edit Maximum password age to 45 days, and put 14 characters as minimum length (It will not let me select 15).

Now, here is the thing: Above the "Small Business Server Domain Password Policy" I have a "Default Domain Policy" that is set to 42 days for max age and 7 characters for minimum length.

There is a conflict here... why is it that when I open these to edit, GPO Editor is opened?

How do I trace these conflicting policies down and get the result that I want?!

0
Comment
Question by:mnbookman
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
5 Comments
 
LVL 23

Assisted Solution

by:ormerodrutter
ormerodrutter earned 100 total points
ID: 33466416
Anything you manually entered surecede the default policy.

For example, if you don't enter anything the Default policy will kick in. But if you have a customer policy it will override the existing Default policy.
0
 

Author Comment

by:mnbookman
ID: 33466623
I took over for someone else and... a year later I'm still trying to figure things out. :)

How do I trace policies to see which ones are in effect?
0
 
LVL 26

Accepted Solution

by:
DrDave242 earned 400 total points
ID: 33470478
First, the easy question: the GPO Editor gets opened when you edit a GPO because...that's the tool that is used to edit GPOs.  :)

Now the rest.  You can see which policy takes precedence in the Group Policy Management Console.  In this case, both policies should be applied at the domain level (since that's the only place you can specify a password policy in 2003), so click on the domain name in the left pane of the console.  Then click on the Group Policy Inheritance tab in the right pane.  Policies higher in the list take precedence over those lower in the list.  (There are exceptions to this rule, such as when a policy is given the Enforced/No Override setting, but that's not likely true in your case.)
0
 

Author Comment

by:mnbookman
ID: 33479997
Thanks DrDave242, with your help, I may have this licked... Is there any way to check account statistics for individual users - for example, how many days are left before their password change?

I was completely misunderstanding how policies are laid out. Under Domains ->domain.local, I thought each policy was a SUMMARY, and wasn't understanding that when I right clicked on one and selected 'Edit' that I was only editing THAT policy. I thought each edit was taking me to the same place.

Now I understand there is a hierarchy.
0
 
LVL 26

Assisted Solution

by:DrDave242
DrDave242 earned 400 total points
ID: 33480198
The Account Lockout and Management Tools should give you the information you need:

http://www.microsoft.com/downloads/details.aspx?FamilyId=7AF2E69C-91F3-4E63-8629-B999ADDE0B9E&displaylang=en

This article gives some information on using the tools:

http://www.windowsecurity.com/articles/Implementing-Troubleshooting-Account-Lockout.html
0

Featured Post

On Demand Webinar - Networking for the Cloud Era

This webinar discusses:
-Common barriers companies experience when moving to the cloud
-How SD-WAN changes the way we look at networks
-Best practices customers should employ moving forward with cloud migration
-What happens behind the scenes of SteelConnect’s one-click button

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In the event you manage a Small Business Server 2003, and you are audited for PCI compliance, there are several changes you must make in order to pass the audit. I can take no credit for discovering any of these fixes or workarounds, but there is no…
This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Small Business Server 2011. NOTE: This guide has been written using the preview version of SBS2011 therefore some of the screens may …
In this brief tutorial Pawel from AdRem Software explains how you can quickly find out which services are running on your network, or what are the IP addresses of servers responsible for each service. Software used is freeware NetCrunch Tools (https…
Add bar graphs to Access queries using Unicode block characters. Graphs appear on every record in the color you want. Give life to numbers. Hopes this gives you ideas on visualizing your data in new ways ~ Create a calculated field in a query: …

705 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question