A
arno schoblocher
hello!
win2000 SP3 terminal server
first, i have to say that we have only one terminal server and one print
server, there's no extra domain-controller. it took a while and some group
policies to find out that i have a problem if terminal-server =
domain-controller, this may have caused the problem.
my problem is, that the password policies do not work at all, no matter what
i do.
what i have now are group policies on
- the domain (here i set the password policies)
- the domain-controller (i deactivated password policies in the mean time)
- the site (here's the main policiy to lock down the server, deaktivate
lot's of stuff of the desktop/startmenu etc.)
i have to have 2 policies for 2 user groups because the users should have a
lot of rights on their _PC_ but no rights on the _terminal server_. (if i
have only 1 policy then users cannot work properly on their pc!). so, every
user has 2 usernames, one to logon to the pc, one to logon on the terminal
server.
in detail:
- on the site i locked down the sessions with the terminal-server-usernames,
and i have a policy for the pc-usernames here
- on the domain i have the policy for the terminal-server-usernames. from
KB-articles i know that the password policy _must_ be set for the
default-domain-policy (KB 269236).
- on the domain-controller OU i have some settings that are not directly
connected with locking down the user-session, the folder redirection, hiding
local drives and some settings are the same as on the site (what may be a
problem).
so, some paremters are defined twice. i had problems with "disconnected"
group policies (i had to unlink and link them again according to
www.evintid.net, eventid 1000 userenv, How to unlink a windows 2000 group
policiy).
secedit /refreshpolicy user_policy /enforce
secedit /refreshpolicy machine_policy /enforce
plus rebooting did not work.
so, how can i make my password policies work? i would like to set the length
and complexity etc. but changes do not work.
thank you
arno
win2000 SP3 terminal server
first, i have to say that we have only one terminal server and one print
server, there's no extra domain-controller. it took a while and some group
policies to find out that i have a problem if terminal-server =
domain-controller, this may have caused the problem.
my problem is, that the password policies do not work at all, no matter what
i do.
what i have now are group policies on
- the domain (here i set the password policies)
- the domain-controller (i deactivated password policies in the mean time)
- the site (here's the main policiy to lock down the server, deaktivate
lot's of stuff of the desktop/startmenu etc.)
i have to have 2 policies for 2 user groups because the users should have a
lot of rights on their _PC_ but no rights on the _terminal server_. (if i
have only 1 policy then users cannot work properly on their pc!). so, every
user has 2 usernames, one to logon to the pc, one to logon on the terminal
server.
in detail:
- on the site i locked down the sessions with the terminal-server-usernames,
and i have a policy for the pc-usernames here
- on the domain i have the policy for the terminal-server-usernames. from
KB-articles i know that the password policy _must_ be set for the
default-domain-policy (KB 269236).
- on the domain-controller OU i have some settings that are not directly
connected with locking down the user-session, the folder redirection, hiding
local drives and some settings are the same as on the site (what may be a
problem).
so, some paremters are defined twice. i had problems with "disconnected"
group policies (i had to unlink and link them again according to
www.evintid.net, eventid 1000 userenv, How to unlink a windows 2000 group
policiy).
secedit /refreshpolicy user_policy /enforce
secedit /refreshpolicy machine_policy /enforce
plus rebooting did not work.
so, how can i make my password policies work? i would like to set the length
and complexity etc. but changes do not work.
thank you
arno