Sorry if this is the wrong group. Let me know if I should be somehwere
else.

I'm currently in a single W2K domain model. If I add a domain to my
forest, can I apply different account restrictions on any user objects
I create in the new domain? Or am I forced to take the policy from the
root domain?

E.G.

mydomain.com is set to 10 failed attempts, 30 miute lock out, 9
character passwords, max age of 60 days

I want to create childdomain.mydomain.com with 3 failed attemps, 60
minute lockout, 12 character complex password.


TIA

Darren

Re: Accont Security policy by Steven

Steven
Mon Jan 12 17:54:48 CST 2004

Domain account policy is defined at the domain level, so yes you can have a different
policy for another domain that will apply to ALL users in that domain. -- Steve

http://support.microsoft.com/default.aspx?kbid=255550

"Darren" <dropittome@yahoo.com> wrote in message
news:5f420f00.0401121501.5b3c2b2f@posting.google.com...
> Sorry if this is the wrong group. Let me know if I should be somehwere
> else.
>
> I'm currently in a single W2K domain model. If I add a domain to my
> forest, can I apply different account restrictions on any user objects
> I create in the new domain? Or am I forced to take the policy from the
> root domain?
>
> E.G.
>
> mydomain.com is set to 10 failed attempts, 30 miute lock out, 9
> character passwords, max age of 60 days
>
> I want to create childdomain.mydomain.com with 3 failed attemps, 60
> minute lockout, 12 character complex password.
>
>
> TIA
>
> Darren