We help IT Professionals succeed at work.
Get Started

Setting password restrictions in 2003 Group Policy

419 Views
Last Modified: 2012-06-27
Hi

I look after a single Windows 2003 domain for our small office.  Some time ago I edited the default domain policy using the Group Policy Management snap-in via my XP workstation to enforce a simple password policy.  Domain passwords were set to expire after 90 days and to enforce new complexity rules but it's been over 90 days now and it hasn't kicked in.  It's the first time I've had to tinker with group policies so I've probably done something dumb.

If I select Default Domain Policy under the domain's Group Policy Objects there are 4 tabs in the right hand screen.  Under Scope our single domain is listed under Links and  with both Enforced and Link Enabled listed as Yes.  Under Security Filtering it states that the settings in this GPO apply to Authenticated Users and Domain USers.  In the Details tab it states that the GPO status is Enabled.  The Details tab doesn't appear to show anything relevant and in the Delegation tab it states the following permissions, none of which are inherited.

Authenticated Users - Read (from Security Filtering)
Domain Admins - Edit, delete, modify security
Domain Users - Read (from Security Filtering)
Enterprise Admins - Edit, delete, modify security
Enterprise Domain Controllers - Read
System - Edit, delete, modify security

If I right-click on the GPO or the link located under the domain name in the tree and go to View I get the Group Policy 'browser'.  The bit I've edited is under Default Domain Policy--Computer Configuration--Windows Settings--Security Settings--Account Policies--Password Policy.  I've set the following

Enforce password history - 3
Max password age - 90
Min password age - 30
Min password length - 7
Password must meet complexity requirements - Enabled
Store password using reversible encryption - Disabled

I don't know if I've provided enough information but I'd be grateful if someone with more experience in these things could point out where I've dropped a nut. If all appears well then I'd like to know why it hasn't woken up.

Thanks
Comment
Watch Question
Network Engineer
CERTIFIED EXPERT
Commented:
This problem has been solved!
Unlock 1 Answer and 20 Comments.
See Answer
Why Experts Exchange?

Experts Exchange always has the answer, or at the least points me in the correct direction! It is like having another employee that is extremely experienced.

Jim Murphy
Programmer at Smart IT Solutions

When asked, what has been your best career decision?

Deciding to stick with EE.

Mohamed Asif
Technical Department Head

Being involved with EE helped me to grow personally and professionally.

Carl Webster
CTP, Sr Infrastructure Consultant
Ask ANY Question

Connect with Certified Experts to gain insight and support on specific technology challenges including:

  • Troubleshooting
  • Research
  • Professional Opinions
Did You Know?

We've partnered with two important charities to provide clean water and computer science education to those who need it most. READ MORE