Account policies are only read at the domain level and you can only have one
password policy per domain. Any policies applied at the OU level will only
apply to the local machine account policy.
See the following for more info
255550 Configuring Account Policies in Active Directory
http://support.microsoft.com/?id=255550
221930 Domain Security Policy in Windows 2000
http://support.microsoft.com/?id=221930
--
--
Tim Hines, MCSE, MCSA
Windows 2000 Directory Services
=====================================================
When responding to posts, please "Reply to Group" via
your newsreader so that others may learn and benefit
from your issue.
=====================================================
This posting is provided "AS IS" with no warranties, and confers no rights.
Kirk H. said:
I have a Win2k AD domain in native mode and want to test password
complexity on an OU before applying to the entire domain. The complex
password policy is applied when I logon to the local machine but not when I
logon with a domain user which is a member of the OU and security group
within that OU. The machine account is also a member of the OU and the
security group I created. How can I apply the policy to the domain account?
BTW machine is Win2k Pro.