[Last Call] Learn about multicloud storage options and how to improve your company's cloud strategy. Register Now

x
?
Solved

Setup Fine-Grained Password Policy

Posted on 2013-06-12
8
Medium Priority
?
596 Views
Last Modified: 2013-07-12
Windows 2008 R2 ADDS

Inherited setup were previous sysadmin, disabled all pwd security on the domain... also removed from 'Default Domain Policy' .....I am restoring this back to defaults...however a group of users (say Global security group ALL-XYZ) requires a different password policy than the default, these users are spread across several OUs ann sub-OUs

...so i setup a FGPP with ADSI and assigned the group.....but some where I read about Shadow Groups....what are they, how do they apply to FGPP, are they the same as a regular group?

here is what I did to setup the FGPP with ADSI..
http://akrameleyan.wordpress.com/2013/01/06/why-and-how-to-use-fine-grained-password-policies/

Am I missing something...Do I have to link the user OSs? How since this is not done in GPO Manager?? I don't have a test enviornment so want to be sure before I execute
0
Comment
Question by:BigBadWolf_000
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
8 Comments
 
LVL 57

Assisted Solution

by:Mike Kline
Mike Kline earned 1000 total points
ID: 39242241
Shadow groups are not real groups.  They are groups that people create using scripts for example automatically put every person in OU X into Group X.  

By the way if you have one Windows 8 or Windows 2012 box (member server is fine) setup you can use AD Admin Center to work with FGPP...much easier than adsiedit.

Thanks

Mike
0
 
LVL 10

Accepted Solution

by:
Zenvenky earned 1000 total points
ID: 39243427
0
 
LVL 14

Author Comment

by:BigBadWolf_000
ID: 39244827
mkline71:  "A shadow group is a global security group that is logically mapped to an OU to enforce a fine-grained password policy. "

Still not clear...how do I map a shadow group to an OU? Does'nt a group created via PS/script still show as a group in the Windows interface?

zenvenky: Very good links thanks!

both: so to summarize, unless I need to bind a PSO to an OU, I don't need to worry about shadow groups correct?
0
Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

 
LVL 57

Expert Comment

by:Mike Kline
ID: 39244844
It does so you would create/script your group and have that PSO (passwords setting object) apply to that group.

The group in this example would contain every user in that OU...not actually mapped to the OU.  PSOs can only be applied to users/groups not OUs.

Thanks
Mike
0
 
LVL 14

Author Comment

by:BigBadWolf_000
ID: 39275470
mike: I have a (nested) Group, say 'All_Contractors'
I have a GPO setup with the password policy - Linked location is the root OU, Security Filtering is the 'All_Contractors' group

In the PSO via adsiedit... msDS-PSOAppliesTo...points to 'All_Contractors'
and I verified that the appropriate user has attrib msDS-ResultantPSO pointing to 'All_Contractors'

Should I do something else to connect the PSO to the Group via GPO? or am I done...wont be able to tell till I change the policy settings :)
0
 
LVL 14

Author Comment

by:BigBadWolf_000
ID: 39284873
Hi mkline71 : could you please provide feedback on my quesyion above...thanks :)
0
 
LVL 57

Expert Comment

by:Mike Kline
ID: 39284902
You should be done, by the way if you get one Windows 8 or 2012 box (member server is fine) you can use the new AD Admin Center which makes working with FGPP much easier.

Thanks

Mike
0
 
LVL 14

Author Closing Comment

by:BigBadWolf_000
ID: 39322154
Thanks!
0

Featured Post

Visualize your virtual and backup environments

Create well-organized and polished visualizations of your virtual and backup environments when planning VMware vSphere, Microsoft Hyper-V or Veeam deployments. It helps you to gain better visibility and valuable business insights.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Had a business requirement to store the mobile number in an environmental variable. This is just a quick article on how this was done.
Group policies can be applied selectively to specific devices with the help of groups. Utilising this, it is possible to phase-in group policies, over a period of time, by randomly adding non-members user or computers at a set interval, to a group f…
This tutorial will walk an individual through locating and launching the BEUtility application to properly change the service account username and\or password in situation where it may be necessary or where the password has been inadvertently change…
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …
Suggested Courses

650 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question