Results 1 to 5 of 5

Thread: Domain Password Policy not being applied

  1. #1
    Registered+
    Join Date
    Feb 2006
    Posts
    30
    Thanks
    0
    Thanked
    0 times in 0 posts

    Domain Password Policy not being applied

    Hi All,

    Got a bit of a problem here with our domain passwords not expiring, first I'll give you the background. We've got two domains "A" and "B". B is a child domain of domain A. Both have multiple DC's / GC's and both are run from Win2003 SP2 and both also have Exchange 2003 (so schema has been extended).

    Domain A has the "default domain policy" modified so max password age is set to 90 days, and in domain B the same is set to 180 days. Both the default domain policies are linked to the root of their appropriate domains.

    The problem I've got is that in domain A users' passwords never expire, but domain B works fine. I've checked the policy is being applied using rsop.msc, and it is being pulled down fine to every user / workstation. I've also checked that the users' accounts are not set for their password never to expire. Everything looks fine. Also refreshing the policies using gpudate runs fine with no errors recorded in the event logs.

    Where things get really odd is when doing a vbs query to read a users "maxPwdAge" field, it always returns 0, never 90. I'm rather stumped over this one, I've checked and double checked that their are no other policies in domain A at all that specify password expiry. But even if there were, rsop.msc still reports the policy as being set to 90 days.

    Any ideas?

    Cheers,

    Jon
    Last edited by javers; 25-06-2007 at 10:17 AM.

  2. #2
    Registered+
    Join Date
    Feb 2006
    Posts
    30
    Thanks
    0
    Thanked
    0 times in 0 posts
    bump

  3. #3
    Administrator Moby-Dick's Avatar
    Join Date
    Jul 2003
    Location
    There's no place like ::1 (IPv6 version)
    Posts
    10,665
    Thanks
    53
    Thanked
    384 times in 313 posts
    Is replication happy between all the GC's ?
    my Virtualisation Blog http://jfvi.co.uk Virtualisation Podcast http://vsoup.net

  4. #4
    Administrator Moby-Dick's Avatar
    Join Date
    Jul 2003
    Location
    There's no place like ::1 (IPv6 version)
    Posts
    10,665
    Thanks
    53
    Thanked
    384 times in 313 posts
    Check the security permissions for the authenticated users group for the Default domain policy. They should have 'apply group policy'


    If the policy has been configured correctly then the only way it wont be applied is if you don't have permissions.
    my Virtualisation Blog http://jfvi.co.uk Virtualisation Podcast http://vsoup.net

  5. #5
    Pedandic mo-fo IAmATeaf's Avatar
    Join Date
    Jul 2006
    Location
    South of the Watford Gap!
    Posts
    963
    Thanks
    2
    Thanked
    22 times in 22 posts
    • IAmATeaf's system
      • Motherboard:
      • Asus P5Q Deluxe
      • CPU:
      • Q6600@3.25
      • Memory:
      • 4 x 2GB Corsair 6400C5DHX XMS2
      • Storage:
      • 2 x 0.5TB 7200.12, 2 x 1.5TB 7200.11
      • Graphics card(s):
      • Gigabyte GTX460 OC
      • PSU:
      • Corsair HX520
      • Case:
      • Lian Li PC6089B
      • Operating System:
      • Windows 7 Pro x64
      • Monitor(s):
      • Samsung T240 24"
      • Internet:
      • 6Mb ADSL Max
    Also check the time on the servers and workstations, if the clocks are out by more then an hour then this can lead to problems in applying domain policies.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Replies: 5
    Last Post: 22-03-2007, 10:00 PM
  2. Cannot join domain
    By nimblegimble in forum Help! Quick Relief From Tech Headaches
    Replies: 13
    Last Post: 19-09-2006, 09:03 AM
  3. "Whois hijacking my domain research?"
    By Steve in forum HEXUS News
    Replies: 10
    Last Post: 21-07-2006, 05:22 PM
  4. Replies: 23
    Last Post: 12-09-2005, 03:27 PM
  5. Win2k domain gubbins...
    By Neo_VR in forum Software
    Replies: 2
    Last Post: 13-03-2005, 03:41 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •