Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

Fine Grained  password policy will not allow groups to be assigned to it.

Posted on 2016-10-19
4
Medium Priority
?
24 Views
Last Modified: 2016-10-20
Hey Guys,

I set up a password policy in Active directory.  Our domain is native 2012 r2 functional level.

I can assign users to the policy under the "Directly Applies TO" section.

However, I cannot apply it to a group.  I get an error that the group object cannot be found even though it does.  When I enter a partial name, it only lists user objects even though user and group objects are both checked.  I have tried from the root of the directory as well as the container that the group is located in.

Has anyone else seen this behavior and know what the fix is?
0
Comment
Question by:horsemenl
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
4 Comments
 

Author Comment

by:horsemenl
ID: 41850064
A quick update.

What is weird is that I can go to the Password Settings Container under Active Directory Users and Computers and add the DN of the group under the attribute msDS-PSOAppliesTo.

Does anyone else see groups when trying to apply the password policy under the Active Directory Administrative Center?
0
 

Author Comment

by:horsemenl
ID: 41850891
Another update:

Even though I added the group to the msD-PSOAppliesTo attribute, it does not work.  It only works on individual users, so my initial issue is still in play.
0
 

Author Comment

by:horsemenl
ID: 41851916
I have included a screenshot of the error

Screenshot of the error
0
 

Accepted Solution

by:
horsemenl earned 0 total points
ID: 41852049
I found the resolution.

Our groups are Universal and you can only apply FGPP to Global groups.  I changed the group to Global and then was able to apply it normally.
0

Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Group policies can be applied selectively to specific devices with the help of groups. Utilising this, it is possible to phase-in group policies, over a period of time, by randomly adding non-members user or computers at a set interval, to a group f…
Microsoft Office 365 is a subscriptions based service which includes services like Exchange Online and Skype for business Online. These services integrate with Microsoft's online version of Active Directory called Azure Active Directory.
In this Micro Tutorial viewers will learn how to restore single file or folder from Bare Metal backup image of their system. Tutorial shows how to restore files and folders from system backup. Often it is not needed to restore entire system when onl…
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…

609 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question