Results 1 to 9 of 9

Thread: Password Policy not applying to the domain

  1. #1
    PreviousPoster is offline 100+ Helpful Posts! 50+ Helpful Posts
    Join Date
    Dec 1969
    Posts
    1,254

    Default

    Hello,

    We edited the default domain policy to include a password policy (e.g., minimum 8 characters required) and then enforced it.

    We then applied this default domain policy to domain users.

    Finally, we replicated our domain controllers and ensured it all had the same password policy and they all did.

    However, when we logged in as a domain user and proceeded to change the password to just 4 characters only, it allowed the password to be changed without prompting an error message stating a minimum of eight characters required.

    We have the exact same password policy set up in our test environment and it got enforced there, but we don't know why the password policy is not being enforced in our production environment.


    Can anyone please provide us with help on how we can resolve the above issue?

  2. #2
    PreviousPoster is offline 100+ Helpful Posts! 50+ Helpful Posts
    Join Date
    Dec 1969
    Posts
    1,254

    Default

    Could it be, that the policy you edited (maybe "Default Domain Policy" is NOT the GPO with the highest priority in the domain (the one in the top of the list)...?

    The Domain Account policies are assigned from the policy in the domain with the highest priority - not necessarily the one called "Default Domain Policy"... Could this be the issue you have?

  3. #3
    JerryC is offline 100+ Helpful Posts! 50+ Helpful Posts
    Join Date
    Dec 1969
    Posts
    231

    Default

    And it shouldn't require the Enforced setting to be mandatory for domain accounts. Also, as a domain 'root level' GPO setting, it'll also apply to local accounts on your devices (though at lower OU levels, other GPOs could override those Account Policy settings..though again..only for local accounts).

  4. #4
    gpoguy is offline 10+ Helpful Posts Happy to be helping others
    Join Date
    Dec 1969
    Posts
    13

    Default

    Also, make sure that you don't have Block Inheritance set on your Domain Controllers OU.
    Additionally, you may also want to check the value of the password policy as it appears in AD, since this is the value that is used by users authenticating to the domain. You can see this by using a tool like ADSIEdit to view the properties on the domain "NC Head" on the PDCe DC. That's the domain object dc=company,dc=com. The attribute minPwdLength stores the current password length.

  5. #5
    PreviousPoster is offline 100+ Helpful Posts! 50+ Helpful Posts
    Join Date
    Dec 1969
    Posts
    1,254

    Default

    We checked all that and it is still not taking. We even went as far as adding the password policy to all GPO's, but still have no success. We verified that everything else in the policies are working and ran gpresult and saw that were getting applied.

  6. #6
    gpoguy is offline 10+ Helpful Posts Happy to be helping others
    Join Date
    Dec 1969
    Posts
    13

    Default

    so, you checked the Domain NC Head and it still shows the old length?

  7. #7
    PreviousPoster is offline 100+ Helpful Posts! 50+ Helpful Posts
    Join Date
    Dec 1969
    Posts
    1,254

    Default

    Where is the Domain NC Head located?

  8. #8
    gpoguy is offline 10+ Helpful Posts Happy to be helping others
    Join Date
    Dec 1969
    Posts
    13

    Default

    See my description above. Its the properties on the domain AD object that you can see using ADSIEdit.

  9. #9
    PreviousPoster is offline 100+ Helpful Posts! 50+ Helpful Posts
    Join Date
    Dec 1969
    Posts
    1,254

    Default

    Quote Originally Posted by gpoguy
    See my description above. Its the properties on the domain AD object that you can see using ADSIEdit.
    We've viewed the values in ADSIEdit and they are 0's. Not the values we set in group policy.

    Does anyone know what "dsCore Propgation Data attribute does"? It has an old date value from year ago.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  

Search Engine Friendly URLs by vBSEO