Account password policy not applied on all domain controlers


hello,

i have following problem:

* have default domain policy linked @ domain level.

* domain controllers in same ou (domain controllers)

* no block inheritance enabled on domain controllers ou

* default domain policy set enforce. , have no other password policies

* domain functional level 2003

dc1 getting default domain policy + pw policy

according rsop and result dc2 , dc3 getting default domain policy not account policy's ( password policy

any idea?

thanks,

arjan

hi arjan,

based on research, in each domain, gpmc uses same domain controller operations in domain, pdc default, in order avoid synchronization issues.

would please tell dc1 pdc emulator?

if yes, behavior normal, can refer kb article below:

some security policies displayed "not defined" in rsop snap-in on windows server 2003, 2008 or 2008 r2 based domain controller

http://support.microsoft.com/kb/927908/en-us

you can verify if account policies have been replicated dc2 , dc3 running net accounts/domain command on them.

more information you:

group policy replication , domain controller selection (group policy infrastructure)

http://technet.microsoft.com/en-us/library/cc779403(v=ws.10).aspx

i hope helps.

best regards,

amy wang



Windows Server  >  Windows Server General Forum



Comments

Popular posts from this blog

WIMMount (HSM) causing cluster storage to go redirected (2012r2 DC)

Failed to delete the test record dcdiag-test-record in zone test.com

Azure MFA with Azure AD and RDS