[Last Call] Learn about multicloud storage options and how to improve your company's cloud strategy. Register Now

x
?
Solved

GPO not overridding Default Domain policy

Posted on 2013-11-07
5
Medium Priority
?
469 Views
Last Modified: 2013-11-07
Scenario:
2008 domain structure. I have a Default Domain policy defining [computer configuration>Policies>windows settings>security settings>password policy>Max password age = 45]
I have OU created called restricted. I want to have the USERS in that OU have a policy of 30 days. But I want the rest of the settings in the default domain policy to still apply to these users.
I have created the GPO, applied it to the OU, the group policy inheritance tab in Group Policy Management.msc shows the two policies, both are set to Enforce, both are set to Enabled. Precedence 1 is the default domain policy and 2 is the GPO created for that OU. I force AD replciation, do a gpoupdate /force on the users workstation, but rsop.msc still shows the 45 days.

If the order of precedence is Local / Site / Domain / OU what would be preventing that GPO from changing it to 30?

Thanks,
chuck
0
Comment
Question by:fcbc
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
5 Comments
 
LVL 21

Accepted Solution

by:
oleggold earned 2000 total points
ID: 39630724
0
 
LVL 21

Assisted Solution

by:oleggold
oleggold earned 2000 total points
ID: 39630726
0
 
LVL 21

Assisted Solution

by:oleggold
oleggold earned 2000 total points
ID: 39630730
0
 
LVL 21

Assisted Solution

by:oleggold
oleggold earned 2000 total points
ID: 39630735
0
 
LVL 70

Expert Comment

by:KCTS
ID: 39630761
You can only have one password policy per domain unless you implement a fine grained password policy
0

Featured Post

Get free NFR key for Veeam Availability Suite 9.5

Veeam is happy to provide a free NFR license (1 year, 2 sockets) to all certified IT Pros. The license allows for the non-production use of Veeam Availability Suite v9.5 in your home lab, without any feature limitations. It works for both VMware and Hyper-V environments

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Uncontrolled local administrators groups within any organization pose a huge security risk. Because these groups are locally managed it becomes difficult to audit and maintain them.
A bad practice commonly found during an account life cycle is to set its password to an initial, insecure password. The Password Reset Tool was developed to make the password reset process easier and more secure.
Windows 8 came with a dramatically different user interface known as Metro. Notably missing from that interface was a Start button and Start Menu. Microsoft responded to negative user feedback of the Metro interface, bringing back the Start button a…
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…

650 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question