I have 100+ computers running XP divided into multiple OUs. My password policy is the same for everyone and is defined in the Default Domain Policy. Just in case, I also applied the same password policy in the OUs GP as well. Gpresult shows that the policy for the OU and Default Domain are applying, but users can still have simple, short, and even blank passwords! Here is a sample of a typical gpresult query.
COMPUTER SETTINGS
——————
CN=computer,OU=ouname,DC=domain,DC=com
Last time Group Policy was applied: 12/18/2007 at 2:08:20 PM
Group Policy was applied from: server.domain.com
Group Policy slow link threshold: 500 kbps
Applied Group Policy Objects
—————————–
wsusgpo
Default Domain Policy
The following GPOs were not applied because they were filtered out
——————————————————————-
Local Group Policy
Filtering: Not Applied (Empty)
The computer is a part of the following security groups:
——————————————————–
BUILTIN\Administrators
Everyone
BUILTIN\Users
NT AUTHORITY\NETWORK
NT AUTHORITY\Authenticated Users
computer name
Domain Computers
USER SETTINGS
————–
CN=user,OU=ouname,DC=domain,DC=com
Last time Group Policy was applied: 12/18/2007 at 2:09:01 PM
Group Policy was applied from: server.domain.com
Group Policy slow link threshold: 500 kbps
Applied Group Policy Objects
—————————–
wsusgpo
Default Domain Policy
The following GPOs were not applied because they were filtered out
——————————————————————-
Local Group Policy
Filtering: Not Applied (Empty)
The user is a part of the following security groups:
—————————————————-
Domain Users
Everyone
BUILTIN\Users
NT AUTHORITY\INTERACTIVE
NT AUTHORITY\Authenticated Users
LOCAL
I have been able to change user GP settings and they apply. GPMC shows all policies as NOT enforced, links enabled, all paths correct, all GPOs enabled and linked properly.
Uers are starting to figure this out so I need a fix fast!
Thanks!