Solved

Windows 2008 Fine Grant Passwords and Delegation

Posted on 2010-08-23
2
494 Views
Last Modified: 2012-08-13
Right now I have a 2008 parent child domain. MY parent domain is just a place holder and all of my user account are in my child domain. Right now my help Desk has the ability to reset user passwords.
Today I found out that management wants to how have two password policies for our child domain.
1) one for regaulr users and the other for admins
2) The help desk also needs the ability to unlock user accounts

how can I setup two password policies? I know you can do this in 2008 but I never did it before? Ca nI have 2 password policies in a child domain only? What additonal permissions do i need to give my help desk in order for them to unlock uer accounts?

Can I use dsquery or dsget to dump all current A.D permission groups currently have...
0
Comment
Question by:compdigit44
2 Comments
 
LVL 53

Accepted Solution

by:
Will Szymkowski earned 500 total points
ID: 33506650
In order to use Fine Grained Password Policy you will need to make sure that first you are running domain functional level 2008. If this is true follow the step-by-step guide here and you should be on your way.
http://technet.microsoft.com/en-us/library/cc770842(WS.10).aspx
and
http://technet.microsoft.com/en-us/library/cc770394(WS.10).aspx
0
 
LVL 19

Author Comment

by:compdigit44
ID: 33509654
It is ok to run a fine grain pws policy in a child domain and not the parent?

What permission do I need to give my help desk users in AD in order for them to unlock accounts?

0

Featured Post

Is Your AD Toolbox Looking More Like a Toybox?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
server 2012 and 2008 3 31
Windows mapped drive communications - Secure? 5 42
Need powershell script to filter accounts in a domain 6 24
Azure Expertise required 1 26
This article runs through the process of deploying a single EXE application selectively to a group of user.
This article explains how to install and use the NTBackup utility that comes with Windows Server.
This tutorial will give a an overview on how to deploy remote agents in Backup Exec 2012 to new servers. Click on the Backup Exec button in the upper left corner. From here, are global settings for the application such as connecting to a remote Back…
This tutorial will walk an individual through the steps necessary to configure their installation of BackupExec 2012 to use network shared disk space. Verify that the path to the shared storage is valid and that data can be written to that location:…

809 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question