Subscribe to Windows IT Pro

 

Get Newsletters

  • Get the Latest News
  • Product Updates
  • Helpful Tricks
  • Productivity Tips

Subscribe Now!

September 27, 2007 12:00 AM

Figuring Out Which GPO’s Policy Is Taking Precedence

Windows IT Pro
InstantDoc ID #96596
Rating: (0)

Q: I recently noticed that I can specify short or even blank passwords for local accounts—even the administrator account—on member servers despite the fact that the Default Domain Policy for our domain requires passwords to be at least eight characters and the Require passwords to meet complexity requirements feature to be enabled. I thought that domain-level settings overrode a computer’s local policy. Why isn’t that happening in this case?

A: The value defined for any policy (e.g., the minimum password length defined as eight) in Group Policy Objects (GPOs) overrides any value defined for the same policy in the computer’s local policy object. A computer’s local policy takes effect only if no applicable GPO in Active Directory (AD) has a defined value for a given policy. However, more than one GPO in AD might define a value for the same policy. For example, one GPO might define eight as the minimum password length while another GPO might define 0.

When a computer applies multiple GPOs, it does so starting at the root of the domain and working down through the branch of organizational units (OUs) leading to the computer’s account. Policies defined higher in the OU structure are overridden by conflicting policies in lower OUs. The logic is that lower GPOs are closer to the computer, so their policies should carry more weight.

Most likely, the reason your member servers are allowing simple or blank passwords is that a GPO linked to a lower OU on the path to the servers is overriding the Default Domain Policy, which is linked to the root of the domain and therefore takes less precedence compared to any OU-linked GPOs.

The following are a couple other possible explanations:

  • The permissions on the Default Domain Policy GPO might have been modified so that the member servers lack either Apply Group Policy or Read permissions.
  • An OU on the path to the member servers’ computer objects has the Block policy inheritance feature enabled, which blocks higher GPOs from being applied.
  • A Windows Management Instrumentation (WMI) filter on the Default Domain Policy GPO is excluding the GPO from the member servers.

An excellent free tool to help you diagnose the problem is the Microsoft Management Console (MMC) Group Policy Management Console (GPMC) snap-in, which you can download from http://www.microsoft.com/downloads/details.aspx?FamilyID=0A6D4C24-8CBD-4B35-9272-DD3CBFC81887&displaylang=en.

Related Content:

ARTICLE TOOLS

Comments
    There are no comments to display. Be the first one!
You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

White Papers

Get your Windows 7 deployment off to the right start by implementing PC lockdown. A locked-down environment is easier and cheaper to support since users are less likely to make unnecessary changes to the core system configuration - read more here!

Essential Guides

Is your iSCSI "lossy"? The reality is that most off-the-shelf Ethernet hardware deployed for iSCSI can lose packets, resulting in slow performance or application downtime. Learn how to assess your current iSCSI infrastructure and engineer an advanced iSCSI SAN infrastructure.

Web Seminars

What's the best way to keep your network safe from malware? In this web seminar, security expert Greg Shields suggests an alternative method to the traditional blacklisting approach that is common with anti-virus and anti-malware solutions.

eLearning Series

We bring the experts direct to you to share their real-world perspective and expertise. During each event, three sessions stream in real time, so you can learn, ask questions, and get solutions.
Upcoming event: Getting the Most with Exchange 2010 with Paul Robichaux

Subscribe to Windows IT Pro!

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.