domain admin password
Hello ,i want to remove the acces to change the password for a user who is in the domain admin group,but when everi checked password cant changed ti automatically reverted back ???? is it because of any domanin policy?i want a domain admin cant change the passord .
September 25th, 2009 8:27am

Hi Jayanth,thank you for posting in windows server forums, you can use the below policy and map the appropriate user for the desired access Open Active Directory Users and Computers. In the console tree, right-click the domain or organizational unit that you want to set Group Policy for. Click Properties, and then click the Group Policy tab. Click an entry in Group Policy Object Links to select an existing Group Policy object (GPO), and then click Edit. You can also click New to create a new GPO, and then click Edit. In the console tree, click Password Policy.Where? Group Policy Object [computer name] Policy/Computer Configuration/Windows Settings/Security Settings/Account Policies/Password Policy In the details pane, right-click the policy setting that you want, and then click Properties. If you are defining this policy setting for the first time, select the Define this policy setting check box. Select the options that you want, and then click OK. sainath !analyze
Free Windows Admin Tool Kit Click here and download it now
September 25th, 2009 8:51am

what i meant to say is....a domain admin shold not able to change the password. i selected the tick beside password cantbe changed .but it is changing to the default one automatically, so a domain admin again able to change the password. what may the reason behind this.
September 25th, 2009 10:59am

Hello,never saw this behaviour, think you talk about the account tab on the user account properties, "User cannot change password"? Which additional group member is the account?Best regards Meinolf Weber Disclaimer: This posting is provided "AS IS" with no warranties, and confers no rights.
Free Windows Admin Tool Kit Click here and download it now
September 25th, 2009 1:44pm

Hello Sainath,keep in mind that the password policy has to be set on domain level only, if configured to an OU it has only effect on NOT domain connected machines. Otherwise it will be ignored.To configure password policy on OU level you have the need for 2008 DCs and functional level 2008, to apply Fine grained password policies or some 3rd party application if your OS version is prior 2008.Best regards Meinolf Weber Disclaimer: This posting is provided "AS IS" with no warranties, and confers no rights.
September 25th, 2009 1:47pm

Hi meinolf, thanks for the info , the above info isrelated to prior 2008 servers, i thought this should work fine with windows 2008. i appreciate the way you have explained , thanks onceagain. sainath !analyze
Free Windows Admin Tool Kit Click here and download it now
September 29th, 2009 4:46am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics