Account password policy not applied on all domain controlers
hello,
i have following problem:
* have default domain policy linked @ domain level.
* domain controllers in same ou (domain controllers)
* no block inheritance enabled on domain controllers ou
* default domain policy set enforce. , have no other password policies
* domain functional level 2003
dc1 getting default domain policy + pw policy
according rsop and result dc2 , dc3 getting default domain policy not account policy's ( password policy
any idea?
thanks,
arjan
hi arjan,
based on research, in each domain, gpmc uses same domain controller operations in domain, pdc default, in order avoid synchronization issues.
would please tell dc1 pdc emulator?
if yes, behavior normal, can refer kb article below:
some security policies displayed "not defined" in rsop snap-in on windows server 2003, 2008 or 2008 r2 based domain controller
http://support.microsoft.com/kb/927908/en-us
you can verify if account policies have been replicated dc2 , dc3 running net accounts/domain command on them.
more information you:
group policy replication , domain controller selection (group policy infrastructure)
http://technet.microsoft.com/en-us/library/cc779403(v=ws.10).aspx
i hope helps.
best regards,
amy wang
Windows Server > Windows Server General Forum
Comments
Post a Comment