Lockout Problem

  • Thread starter Thread starter Fred
  • Start date Start date
F

Fred

Hi,

I need a solution to prevent that the accounts of the administrators
(domain admins members) are not locked-out. But I want continue use
Group Policy to lock-out the users. Is there some property in AD?

Help, please,

Fred.
 
That is not possible as domain account/password policy applies to all domain members.
Of course the built in administrator account for the domain can never be locked out
to interactive logon to domain controllers. A common problem is that the threshold is
set too low. MS recommends no less than ten and I have seen recommendations much
higher if password complexity is enabled. A properly configured firewall should help
prevent lockouts to domain accounts from the internet. If you are experiencing
lockouts from malicious users on the lan, you should be able to track them down
eventually and deal with them harshly. The link below is excellent on password and
account security. --- Steve

http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/bpactlck.mspx
 
Back
Top