Apply fine-grained password policy to OU

Our 'Default Domain Policy' contains 6 "Password Policies" -- 1 of which is the "Maximum password age".

We have some OU's, that represent Customers, that require different password ages.

My thought was to create a new GPO in the necessary OU's and set JUST the "Maximum password age" to the required days that Customer requires.

Question: Will the system apply the OU's 1 Password Policy [Maximum password age"] while also applying the 5 Password Policies from the "Default Domain Policy"?

Read these next...

  • Looking for a simple CCTV cam which can be accessed through a URL for staff

    Security

    Hello,I am looking to get a CCTV came, wifi connected and battery operated [or with USB charging] which we can use to overlook over office parking lot.Our staff would like to see the parking lot in the evenings so they can decide to leave a bit early or l...

  • How do you get windows to require a password after timeout??

    Windows

    OK,  I am losing my mind here.I have set up GP to turn on screen saver after 10 minutes, and to password protect. It does not work. It does launch the screen saver, but it does not require a password. I then tried to set the security policy of Inactivity ...

  • Spark! Pro Series - October 14th, 2022 - The Spice it Up and Win Contest

    Spiceworks Originals

    The buzz has been building for weeks and finally the time has come. Everyone likes to win once in a while, right? Even those who would never admit it, have a deep-seated desire to win at something. Last piece of the jigsaw puzzle, best dish at the compa...

  • Snap! Magniber ransomware, Linux desktop, RTX 4090 priority program, Brain Cells

    Spiceworks Originals

    Your daily dose of tech news, in brief. How is Friday already here? Not that I'm complaining, but this week has seemed to fly by. Speaking of time flying by, did you realize that it has been 65 years since the British Computer Society [BCS] was inc...

  • Snap! MSFT's SUG, CommonSpirit Health cyberattack, Cyber Expo, RTX 4080, etc.

    Spiceworks Originals

    Your daily dose of tech news, in brief. While I believe the first commercial cellular network was launched in 1979 by Nippon Telegraph and Telephone [NTT], on October 13, 1983, the first commercial wireless phone call was made [in the U.S.]. It was...

Now that you’ve learned how to administer your environment using Group Policies, it’s time to look at customizing the password settings in your domain. You’ll perform this task using fine-grained password policies, which are also known as Password Settings Objects [PSOs]. The two terms are used interchangeably in this chapter. They enable you to have multiple password policies in the domain, which means your organization saves the cost of having multiple domains. PSOs make security more granular and enable you to apply stricter password requirements to sensitive groups such as your administrators.

The chapter starts with an overview of the concepts surrounding PSOs. After this short theory section, we’ll get back to the practical nature of administering Active Directory by showing you how to create, apply, and test fine-grained password policies.

Once the policies have been created, you need to be able to apply them to your users and groups. There are times when you need to determine the password policy that applies to a particular user. This technique is covered in the last section of the chapter. A number of practical exercises are supplied throughout the chapter, culminating in a lab section to close the chapter.

Before you can learn to manage these objects, you need to understand what they are and what they can do for your environment.

10.1. Fine-grained password policy concepts

10.2. Creating fine-grained password policies

10.3. Determining policies that exist in the domain

10.4. Applying PSOs to users and groups

10.5. Testing the results of a policy applied to a user using PowerShell

10.6. LAB

10.7. Ideas for on your own

Can fine

Fine-grained password policy cannot be applied to an organizational unit [OU] directly. To apply fine-grained password policy to users of an OU, you can use a shadow group. A shadow group is a global security group that is logically mapped to an OU to enforce a fine-grained password policy.

Can you apply a password policy to an OU?

There can be only one password policy if you use the password policy settings in a GPO. A GPO linked to an organizational unit [OU] will not affect domain users located in that OU.

What are fine

Fine-Grained Password Policies allow an administrator to create multiple custom Password Setting Objects [PSO] in an AD domain. In PSOs, you can set the password requirements [length, complexity, history] and account lockout options.

Why would a network administrator choose to set up a fine

By using fine-grained password policies, information security teams and administrators can help strengthen the security of passwords within a domain without increasing the difficulty of the passwords used by standard, nonprivileged users.

Chủ Đề