Solved

Password Policies outside of GPO

Posted on 2016-08-30
7
37 Views
Last Modified: 2016-08-30
I know normally GPOs are used to manage default password policies but there is another way which for the life of me I cannot recall but a former engineer had used. I am trying to locate those settings.  I remember it was "simple" when you knew where to look but I just cannot remember and searches always take me to GPO-related solutions.  

Does anyone know where these settings are?  They are domain-wide I believe.
0
Comment
Question by:sysengny
  • 3
  • 3
7 Comments
 
LVL 26

Accepted Solution

by:
pony10us earned 250 total points
ID: 41776748
Are you referring to fine grain policy available from server 2008 and above using ADSIEdit?
1
 
LVL 38

Assisted Solution

by:Adam Brown
Adam Brown earned 250 total points
ID: 41776789
Aside from ADSIEdit, it *is* possible to set password policy for the domain without a GPO in ADSIEdit by opening the default naming context, expanding it so the domain root folder shows, right click, select properties. All of the password settings applied by a Group Policy that is linked to the domain will show there. You can modify them directly there, just note that any changes you make will be overwritten by group policy either immediately or after a very short period of time unless you make sure there are no GPOs that set group policy linked directly to the domain.
1
 

Author Comment

by:sysengny
ID: 41776912
This was not in ADSIEdit. I am kicking myself for not writing it down last time I saw it.  There is an area where once sets password policies like length, etc.  for a domain. It was outside of the GPO interface but I cant recall the interface I had used.
0
 
LVL 26

Expert Comment

by:pony10us
ID: 41776954
is it possible you are thinking of Active Directory Users and Computers (ADUC)?

Open ADUC
Right click the domain
Select the Attribute Editor tab
Locate and double click the attribute you want to change

If you have permissions (domain admin?) you can change it here however if there is a GPO then it will change it back as Adam stated.
1
 

Author Comment

by:sysengny
ID: 41777023
It was ADSI edit.  The former engineer was playing with PSO's

https://technet.microsoft.com/en-us/library/cc754461(v=ws.10).aspx
0
 

Author Closing Comment

by:sysengny
ID: 41777047
It was a PSO vs GPO.  I could not recall what interface I had used last time to find this (ADSI).  thanks!
0
 
LVL 26

Expert Comment

by:pony10us
ID: 41777065
Glad to help.  We use ADSIEdit to create a fine grained policy on domain admins that is stronger than for regular users.
0

Join & Write a Comment

I had a question today where the user wanted to know how to delete an SSL Certificate, so I thought that I would quickly add this How to! Article for your reference. WHY WOULD YOU WANT TO DELETE A CERTIFICATE? 1. If an incorrect certificate was …
Redirected folders in a windows domain can be quite useful for a number of reasons, one of them being that with redirected application data, you can give users more seamless experience when logging into different workstations.  For example, if a use…
This tutorial will walk an individual through the steps necessary to install and configure the Windows Server Backup Utility. Directly connect an external storage device such as a USB drive, or CD\DVD burner: If the device is a USB drive, ensure i…
This tutorial will show how to configure a new Backup Exec 2012 server and move an existing database to that server with the use of the BEUtility. Install Backup Exec 2012 on the new server and apply all of the latest hotfixes and service packs. The…

747 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now