Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

Password Complexity and Domain Polices

Thread Tools
 
Search this Thread
 
Old May 17, 2002 | 02:22 PM
  #1  
darlodge's Avatar
darlodge
Thread Starter
Scooby Regular
 
Joined: Oct 2001
Posts: 3,449
Likes: 0
From: Lovely Lancing in West Sussex
Post

Let’s set the picture. 2 Windows 2000 Advanced Servers (DC's) 20 Windows 2000 and XP workstations.

We have a Domain policy on our 2 W2K DC's in the AD - Password Complexity. We have this enabled so that all domain user accounts have to comply with this Policy (as expected).

All the local workstations have a generic local administrator password that is only known to our Operations group (me, few other techies and my technical director).

The generic workstation password does not comply with the domain policy, as the password is entered during the build sequence, this bypasses the Domain Policy, as it is not on the domain (at the time of setting the password). Still with me

The problem we have is that an ex-member of staff (a member of the Operations team) changed some one of the local admin passwords on a few of the workstations Whilst we do know the passwords we want to change them back to the generic password again, but Windows will not allow this as the generic password does not meet the requirements of the Domain Policy. I tried removing the effected machines from the Domain and placing them in another Domain and then tried changing the password back, but it did not work, Windows complains about the Password Complexity rules.

Is there a few to get around this other than re-building the box? I don't really want t turn of the policy in the AD on the 2 Servers.

If this is badly worded or does not make a slight bit of sense then let me know and I will elaborate some more.

Many thanks
Darren
Reply
Old May 18, 2002 | 07:15 AM
  #2  
Jeff Wiltshire's Avatar
Jeff Wiltshire
Scooby Regular
 
Joined: Nov 2000
Posts: 2,021
Likes: 1
From: 412 Wheel HP Audi RS4
Post

Wouldn't the simplest thing be to change all the the local admin passwords to comply with your security policy ?
Reply
Old May 18, 2002 | 09:52 AM
  #3  
darlodge's Avatar
darlodge
Thread Starter
Scooby Regular
 
Joined: Oct 2001
Posts: 3,449
Likes: 0
From: Lovely Lancing in West Sussex
Post

That is true, yes. All the passwords should really comply with the policy, but the director is set in his ways and wants them to stay.

Can anybody help?

Darren
Reply
Old May 18, 2002 | 10:03 AM
  #4  
ChristianR's Avatar
ChristianR
Scooby Regular
iTrader: (1)
 
Joined: May 2001
Posts: 6,329
Likes: 1
From: Europe
Post

Take the machine out of the domain and into its own workgroup.

Log in as the local administrator,

start -> run -> mmc <press enter>

go to file -> add/remove snap-in

press add, and select, group policy, and choose local machine.

Go to: Local Computer Policy -> Windows Settings -> Security Settings -> Account Policies -> Password Policy

and disable the "Password must meet complexity requirements" and, change the "minimum password length" to 0



[Edited by ChristianR - 5/18/2002 10:05:30 AM]
Reply
Old May 18, 2002 | 10:10 AM
  #5  
darlodge's Avatar
darlodge
Thread Starter
Scooby Regular
 
Joined: Oct 2001
Posts: 3,449
Likes: 0
From: Lovely Lancing in West Sussex
Post

Thanks Christian,

I'll try that out first thing on Monday morning

Darren
Reply
Old May 20, 2002 | 10:08 AM
  #6  
ChristianR's Avatar
ChristianR
Scooby Regular
iTrader: (1)
 
Joined: May 2001
Posts: 6,329
Likes: 1
From: Europe
Post

Darren - any updates?
Reply
Old May 20, 2002 | 12:50 PM
  #7  
darlodge's Avatar
darlodge
Thread Starter
Scooby Regular
 
Joined: Oct 2001
Posts: 3,449
Likes: 0
From: Lovely Lancing in West Sussex
Post

Sorry Christian, I was a tad busy until now.

Once I removed the machines from our 'main' domain and put them in a test domain and disabled the password policy it worked a treat.

Thanks for you help mate.

Regards
Darren
Reply
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
BLU
Computer & Technology Related
11
Oct 2, 2015 12:53 PM
scoobaru02
Lighting and Other Electrical
9
Sep 29, 2015 10:15 PM
fumbduck
ScoobyNet General
18
Sep 29, 2015 09:16 PM
JackClark
Computer & Technology Related
7
Sep 17, 2015 04:23 PM
Freddy Kruger
ScoobyNet General
6
Apr 11, 2000 09:07 PM




All times are GMT +1. The time now is 02:52 AM.