Solved

Server 2013 password complexity

Posted on 2014-04-07
5
219 Views
Last Modified: 2014-07-22
I have change local security settings and GPO settings we have rebooted several times but our DC is still requiring complex passwords for users in AD, any ideas on how to resolve this we do not wish to use complex passwords.
0
Comment
Question by:jhuntin
5 Comments
 
LVL 31

Accepted Solution

by:
Frosty555 earned 500 total points
ID: 39984822
Look at your resulting set of policies and gpresult. Most likely you did not change the correct GPO, or something is overriding it. Or, the GPO hasn't updated on the server yet. For password complexity of domain users, you should not need to make any changes to local security policy, it will be a GPO change only.

Resulting Set of Policies - allows you to see what the resulting policies were that have been applied to the machine. For each policy, you can see which GPO was responsible for setting it.

Start->run->rsop.msc, and navigate to the password complexity policy.

Also, open a command prompt window and run gpresult /r, this will show you a brief report on which group policies have been applied to the machine. gpresult /h C:\somefolder\somefile.html will generate a more comprehensive HTML report you can open in your web browser to view.
0
 

Author Comment

by:jhuntin
ID: 39985081
Ok I checked them and everything is correct but it still requires complex password I have attached screen shots.
grp-policy.PNG
grp-settings.PNG
0
 
LVL 7

Expert Comment

by:Delete
ID: 39985110
Which GPO are you looking at for the grp-settings.png screenshot?  Is it the Default Domain Controllers policy or the Default Domain Policy?

Have you validated that the settings are disabled in both places?

Can you run rsop.msc from a command prompt to see which GPO is setting that configuration?
0
 

Author Comment

by:jhuntin
ID: 40000775
Ok ran command this is what comes up and the password complex is disabled but we still cant set any password its still want complexity.
grp-settings.PNG
0
 
LVL 54

Expert Comment

by:McKnife
ID: 40000825
Please open up the local policy at each DC using gpedit.msc and look at the same place.
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Lotus Notes – formerly IBM Notes – is an email client application, while IBM Domino (earlier Lotus Domino) is an email server. The client possesses a set of features that are even more advanced as compared to that of Outlook. Likewise, IBM Domino is…
It’s been over a month into 2017, and there is already a sophisticated Gmail phishing email making it rounds. New techniques and tactics, have given hackers a way to authentically impersonate your contacts.How it Works The attack works by targeti…
The video tutorial explains the basics of the Exchange server Database Availability groups. The components of this video include: 1. Automatic Failover 2. Failover Clustering 3. Active Manager
To add imagery to an HTML email signature, you have two options available to you. You can either add a logo/image by embedding it directly into the signature or hosting it externally and linking to it. The vast majority of email clients display l…

680 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question