How to set it so Administrator account can override Group ..

G

Guest

Guest
Archived from groups: microsoft.public.win2000.security (More info?)

Basically, we have about 200 temps coming into our call centre. Their
user names are ie, fr001-fr200. Now we want to set their passwords to
be exactly the same as the username, now for the rest of the domain we
have password policies in place, ie , 7 chars, password complexity. We
want to set it up so that our administrator account can override any
settings in the group policy. We have tried taking removing the policy
from the AD, and no luck, we have tried removing the password
policies, no luck. Either way we cant creat theses users. There are
already users with similar usernames that exist. I removed the GP for
24hrs and it had replicated to all of our sites in aus-nz-can and
still nothing. Anyone?

BTW, obviously win2k domain
 
G

Guest

Guest
Archived from groups: microsoft.public.win2000.security (More info?)

For ALL domain user accounts there can only be one password policy and it is defined
at the domain level. There is no way to selectively override the domain password
policy for domain users. Think of it as a having a built in no override. You should
be able however to temporarily disable the password policy for the task of creating
the user accounts. Normally password policy is configured in Domain Security Policy
though it can be configured via ant GPO in the domain container and the GPO at the
top of the list is the one with the highest priority if there is more than one GPO.
To disable password complexity set it to "disabled" and not undefined and configure
password length appropriately. Then run secedit /refreshpolicy machine_policy
/enforce. If you change password/account policy make sure that block inheritance is
not configured on the domain controller container or the change will not be
implemented. --- Steve


"Brett Brown" <brett.brown@hatsholdings.com.au> wrote in message
news:66aeb1c4.0408171942.66328bd@posting.google.com...
> Basically, we have about 200 temps coming into our call centre. Their
> user names are ie, fr001-fr200. Now we want to set their passwords to
> be exactly the same as the username, now for the rest of the domain we
> have password policies in place, ie , 7 chars, password complexity. We
> want to set it up so that our administrator account can override any
> settings in the group policy. We have tried taking removing the policy
> from the AD, and no luck, we have tried removing the password
> policies, no luck. Either way we cant creat theses users. There are
> already users with similar usernames that exist. I removed the GP for
> 24hrs and it had replicated to all of our sites in aus-nz-can and
> still nothing. Anyone?
>
> BTW, obviously win2k domain