Avatar of Foxglovevol
Flag for Afghanistan asked on

Override Default Domain Password Policy

I have a Win 2008 Domain and have a Group Policy assigned to the root of the domain which sets our default Password Policy for the domain (Length, Age, etc.).  This is of course done via the Computer Configuration settings of the GP, not the user settings.  I need to override this for a specific user and apply a seperate policy for this specific user or group.  

I have created a new OU further down the tree and set it to Block Inheritance using GPMC.MSC.  I then created a new GP and linked it to the OU.  I placed the user in the OU and then replicated using Sites/Serivices and also waited for an hour but I am unable to change the password on the account receiving a message telling me  conform to the default password policy.  

I have also used GPMC to assign a DENY permission for the Default Password Policy, but this also didn't work.

Finally I took a specific computer account and moved it into the OU I created with the Block Inheritance setting, then logged into that computer with the user account and tried to change the user's password by using CTRL-ALT-DEL....however I receive the same error telling me to conforms to the default user password policy.  

I beleive that my issue is the fact that the Default Password Policy is applied at the computer configuration level, and not the user level.  However, I don't see a way around this except perhaps to apply the default password policy at a lower level than root and put the new OU above it so that the policy wouldn't apply.  However, that has some implications to the design of our OUs and GPs that I don't feel are acceptable since I do want this policy to apply to EVERYONE, except the user/group I choose.  If I move the Default Policy down and somehow a User/Computer is inadvertantly put above it they won't get the appropriate policy.  

Any thoughts on how to overcome this obstacle?
IT AdministrationWindows NetworkingNetwork Management

Avatar of undefined
Last Comment

8/22/2022 - Mon

Log in or sign up to see answer
Become an EE member today7-DAY FREE TRIAL
Members can start a 7-Day Free trial then enjoy unlimited access to the platform
Sign up - Free for 7 days
Learn why we charge membership fees
We get it - no one likes a content blocker. Take one extra minute and find out why we block content.
Not exactly the question you had in mind?
Sign up for an EE membership and get your own personalized solution. With an EE membership, you can ask unlimited troubleshooting, research, or opinion questions.
ask a question

I am unfamiliar with them but will look into it now.

It works great. I'm sure this is what you are looking for.
This is the best money I have ever spent. I cannot not tell you how many times these folks have saved my bacon. I learn so much from the contributors.