The Default Domain Policy GPO specifies a value of 3 for the "Account Lockout Threshold", however, the value that is in effect is "5". I've discovered that users are getting the effective value from the Domain Controllers' Local Security Policy (not to be confused with the Default Domain Controllers Policy GPO), which some people say is by design. My first question is: Is this how the system should be working? My second question is, if the answer to the first is "yes", what other settings/values in the Domain Controllers' Local Security Policy might be overriding my Default Domain Policy GPO?
run rsop.msc on domain controller and you should see only default domain policy setting is applied,?
U need to make sure account policy (default domain policy) is latched to domain level with required settings
and if you have blocked inheritance on domain controllers OU, it need to be removed