+ Reply to Thread
Results 1 to 4 of 4

Thread: Default Domain Policy changes not applied

  1. #1
    rwalker76 is offline Getting Started on GPanswers.com
    Join Date
    Dec 1969
    Posts
    9

    Default

    I've made changes to the password policy in both our root domain and child domain which don't seem to have taken effect. Viewing the policy in both GPMC and from a DCs Domain Security Policy both list the new settings, however these are not being applied to users. Changes were made a few days ago, so I'm pretty sure replication shouldn't be the problem.
    All our DCs are 2003 R2, however I have been making use of the 2008 GPPs by managing GPOs from a dedicated 2008 member server.
    I've run both gpotool and GPBPA, both show no problems.
    I use Jiji AD reporting tool for various reports. Interestingly the report from this still shows that both default domain policies still have their original settings, not the new ones.
    Any ideas what I might want to look at next?

    Richard.

  2. #2
    pago is offline 10+ Helpful Posts 20+ Helpful Posts
    Join Date
    Dec 1969
    Posts
    25

    Default

    As password policy and GPP have no relationship I don't regard this as the cause.

    What does the RSOP report show you for an end user client & user ID combination? Do you see the new defined settings in that report?

  3. #3
    pago is offline 10+ Helpful Posts 20+ Helpful Posts
    Join Date
    Dec 1969
    Posts
    25

    Default

    In addition you can check this article "Things to check when your Password Policy doesn’t apply ":
    http://www.frickelsoft.net/blog/?p=137

    Patrick

  4. #4
    rwalker76 is offline Getting Started on GPanswers.com
    Join Date
    Dec 1969
    Posts
    9

    Default

    Thanks for the replies. I found the problem later the same day, but only just thought to update the post - sorry. We had turned on Block Inheritence filters at the Domain Controllers OU, which was stopping the new policy applying. As soon as I switched them off the policies started applying (and the helpdesk phones started ringing...)
    Just checked the link Patrick left and it has this as item 3) to check.
    On a related note, I quite liked having Block Inheritence as a way to protect our DCs but obviously don't want to cause more problems like this in future. Does anybody else use Block Inheritence this way and is there a 'safe' way of doing so? Does Enforce override Block Inheritence? Could I turn back on Block Inheritence at my DC OU, and also Enforce my Default Domain Policy?

    Cheers again,
    Richard.

+ Reply to Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts

Search Engine Friendly URLs by vBSEO