Free Certification Practice Tests and Study Guides
Join Us! | Login | Help





Create a new domain just to apply a GPO... HUH? (294)

 
Post new topic   This topic is locked: you cannot edit posts or make replies.     |##| -> |=|     MC MCSE Certification Forums -> Active Directory Exams
View previous topic :: View next topic  
Author Message
meepzork
New Member
New Member


Joined: 20 Mar 2008
Posts: 17
Location: Irvine, CA

Post subject: Create a new domain just to apply a GPO... HUH? (294)
Posted: Sun May 11, 2008 8:47 pm
Reply with quote

Help others: Review your books and training products here

Im taking 294 tomorrow and im studying right now using Transcenders. Several times I have seen questions asking to apply a GPO to a subset of users or computers. Transcenders says that the correct answer is to create a new domain and apply the GPO there.

WTF?

In my life I have never heard of creating a domain for the sole purpose of managing a particular policy. Please help me understand what im missing here....
_________________
'02 = A+, Network+, 210, 215
'02-'07 = Procrastinate
3/1/08 = 218 MCSA2k
3/30/08 = 292 MCSA2k3
4/28/08 = 293
5/12/08 = 294
Confused = 297 MCSE2k3
Back to top
Offline View user's profile Send private message
joe90
Permanent Fixture
Permanent Fixture


Joined: 31 Mar 2008
Posts: 134
Location: New Zealand

Post subject:
Posted: Sun May 11, 2008 9:12 pm
Reply with quote

Help others: Review your books and training products here

Is this in realtion to password policies?: Off the top of my head you can only have one password policy per domain - one of the MS definitions of a domain is that it is a 'security boundary', so if you wanted a different set of expiry rules for particular groups / ous, well tey would have to be ina different domain.

I butt heads with this about once a year with clients that say have factory PCs that they only want to change password say yearly, while office staff 90 days. Then I put on my Nancy Regan hat and 'just say no'

Or better yet if it is a SOX site I can hide behind that.

And yes Saubournes Oxley even streches its arms all the way dwon to New Zealand
_________________
MCSA W2K W2K3. MBA( Master of Beer Appreciation )
Back to top
Offline View user's profile Send private message
meepzork
New Member
New Member


Joined: 20 Mar 2008
Posts: 17
Location: Irvine, CA

Post subject:
Posted: Sun May 11, 2008 9:57 pm
Reply with quote

Help others: Review your books and training products here

heres the cliff notes version:

the company's written policy says that admins have to have strong passwords. no other user are required to have strong passwords. you have configured a GPO with the appropriate password policy, you must enforce it without imposing unnecessary restrictions on other users.

Their answer (verbatim):
-place all admin user accounts into a separate domain in the existing forest and link the GPO to that domain

There is no mention of any other password policy. Why then wouldnt you just put all the admin accounts into an OU and apply the password policy to that OU?
_________________
'02 = A+, Network+, 210, 215
'02-'07 = Procrastinate
3/1/08 = 218 MCSA2k
3/30/08 = 292 MCSA2k3
4/28/08 = 293
5/12/08 = 294
Confused = 297 MCSE2k3
Back to top
Offline View user's profile Send private message
meepzork
New Member
New Member


Joined: 20 Mar 2008
Posts: 17
Location: Irvine, CA

Post subject:
Posted: Sun May 11, 2008 10:07 pm
Reply with quote

Help others: Review your books and training products here

ive been reading articles online and i guess the short answer is "cuz microsoft said so" eh?

so basically you have the default domain policy.... and anything other than that policy has to go into a different domain. It just doesnt sound right.
_________________
'02 = A+, Network+, 210, 215
'02-'07 = Procrastinate
3/1/08 = 218 MCSA2k
3/30/08 = 292 MCSA2k3
4/28/08 = 293
5/12/08 = 294
Confused = 297 MCSE2k3
Back to top
Offline View user's profile Send private message
Cormac Doyle
Moderator
Moderator


Joined: 08 Nov 2005
Posts: 884
Location: Dublin, Ireland

Post subject:
Posted: Mon May 12, 2008 3:44 am
Reply with quote

Help others: Review your books and training products here

In windows 2003 and earlier ... if you need to apply two different password policies ... you need two different domains.

Windows 2008 supports multiple password policies within the same domain.

This is a very important change ... but yes - in 2003 and earlier, the correct aswer is to create a new domain (or upgrade to 2008)
_________________
LinkedIn profile
Back to top
Offline View user's profile Send private message Send e-mail Visit poster's website AIM Address Yahoo Messenger MSN Messenger
josh26
Needs Serious Help
Needs Serious Help


Joined: 02 Aug 2007
Posts: 525
Location: Australia

Post subject:
Posted: Mon May 12, 2008 4:59 am
Reply with quote

Help others: Review your books and training products here

The rationale is as follows.

It's not so much that you can't create a password policy anywhere in the domain, it's just that there's a caveat. It's a computer policy, not a user policy. And by that, it refers to the computer that actually stores the password being changed.

So you could apply a different policy to a group of users and you all know nothing happens because computer policies do not apply to users.

You could apply it to an OU full of workstations, but then it would take effect on LOCAL accounts created on those workstations. But a domain user doesn't change his password on the PC, he changes it on the domain controller.

Important note here is that it DOES effect accounts on those local PCs, which is sometimes still useful.

The server with the FSMO role PDC Emulator manages password changes to ensure there are no conflicts, so ultimately whatever policy is applied to this machine is the policy that will take effect.

As stated, Windows 2008 does around this, I haven't looked into how.
Back to top
Offline View user's profile Send private message
meepzork
New Member
New Member


Joined: 20 Mar 2008
Posts: 17
Location: Irvine, CA

Post subject:
Posted: Tue May 13, 2008 10:36 am
Reply with quote

Help others: Review your books and training products here

thanks for the heads up guys
_________________
'02 = A+, Network+, 210, 215
'02-'07 = Procrastinate
3/1/08 = 218 MCSA2k
3/30/08 = 292 MCSA2k3
4/28/08 = 293
5/12/08 = 294
Confused = 297 MCSE2k3
Back to top
Offline View user's profile Send private message
Display posts from previous:   
Post new topic   This topic is locked: you cannot edit posts or make replies.     |##| -> |=|     MC MCSE Certification Forums -> Active Directory Exams All times are GMT - 5 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum






IT Showcase