Solved

GPO not overridding Default Domain policy

Posted on 2013-11-07
5
435 Views
Last Modified: 2013-11-07
Scenario:
2008 domain structure. I have a Default Domain policy defining [computer configuration>Policies>windows settings>security settings>password policy>Max password age = 45]
I have OU created called restricted. I want to have the USERS in that OU have a policy of 30 days. But I want the rest of the settings in the default domain policy to still apply to these users.
I have created the GPO, applied it to the OU, the group policy inheritance tab in Group Policy Management.msc shows the two policies, both are set to Enforce, both are set to Enabled. Precedence 1 is the default domain policy and 2 is the GPO created for that OU. I force AD replciation, do a gpoupdate /force on the users workstation, but rsop.msc still shows the 45 days.

If the order of precedence is Local / Site / Domain / OU what would be preventing that GPO from changing it to 30?

Thanks,
chuck
0
Comment
Question by:fcbc
  • 4
5 Comments
 
LVL 21

Accepted Solution

by:
oleggold earned 500 total points
ID: 39630724
0
 
LVL 21

Assisted Solution

by:oleggold
oleggold earned 500 total points
ID: 39630726
0
 
LVL 21

Assisted Solution

by:oleggold
oleggold earned 500 total points
ID: 39630730
0
 
LVL 21

Assisted Solution

by:oleggold
oleggold earned 500 total points
ID: 39630735
0
 
LVL 70

Expert Comment

by:KCTS
ID: 39630761
You can only have one password policy per domain unless you implement a fine grained password policy
0

Featured Post

VMware Disaster Recovery and Data Protection

In this expert guide, you’ll learn about the components of a Modern Data Center. You will use cases for the value-added capabilities of Veeam®, including combining backup and replication for VMware disaster recovery and using replication for data center migration.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Possible fixes for Windows 7 and Windows Server 2008 updating problem. Solutions mentioned are from Microsoft themselves. I started a case with them from our Microsoft Silver Partner option to open a case and get direct support from Microsoft. If s…
Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question