ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    GPO question

    IT Discussion
    6
    36
    1.6k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      JasGot
      last edited by JasGot

      Is your native module exppw.dll correctly registered?

      f06696f6-69f7-4b3f-8c1c-a943260d3267-image.png

      WLS-ITGuyW 1 Reply Last reply Reply Quote 0
      • WLS-ITGuyW
        WLS-ITGuy @JasGot
        last edited by

        @JasGot said in GPO question:

        Is your native module exppw.dll correctly registered?

        f06696f6-69f7-4b3f-8c1c-a943260d3267-image.png

        I’ll get the results you’re asking for and this answer as well tomorrow.

        1 Reply Last reply Reply Quote 0
        • WLS-ITGuyW
          WLS-ITGuy
          last edited by WLS-ITGuy

          @JasGot said in GPO question:

          net accounts /domain

          alt text

          Which is interesting to know but I guess helps me figure out why they can't change their passwords.

          WLS-ITGuyW DashrenderD J 3 Replies Last reply Reply Quote 0
          • WLS-ITGuyW
            WLS-ITGuy @WLS-ITGuy
            last edited by

            This post is deleted!
            1 Reply Last reply Reply Quote 0
            • DashrenderD
              Dashrender @WLS-ITGuy
              last edited by

              @WLS-ITGuy said in GPO question:

              @JasGot said in GPO question:

              net accounts /domain

              alt text

              Which is interesting to know but I guess helps me figure out why they can't change their passwords.

              Assuming you don't have grandular password policies enabled - I don't get how anyone could change their passwords in less than 30 days.

              WLS-ITGuyW 1 Reply Last reply Reply Quote 0
              • WLS-ITGuyW
                WLS-ITGuy @Dashrender
                last edited by

                @Dashrender said in GPO question:

                @WLS-ITGuy said in GPO question:

                @JasGot said in GPO question:

                net accounts /domain

                alt text

                Which is interesting to know but I guess helps me figure out why they can't change their passwords.

                Assuming you don't have grandular password policies enabled - I don't get how anyone could change their passwords in less than 30 days.

                Which is the interesting part as I have a screenshot that has my minimum password age at 7 days but that also might be before I upgraded to 2016 server. Who knows, they days blend together now as I get older.

                1 Reply Last reply Reply Quote 0
                • DashrenderD
                  Dashrender
                  last edited by

                  Show us a picture of your Group Policy Management console, for the root, and the OU where the servers reside.

                  1 Reply Last reply Reply Quote 0
                  • J
                    JasGot @WLS-ITGuy
                    last edited by

                    @WLS-ITGuy said in GPO question:

                    @JasGot said in GPO question:

                    net accounts /domain

                    alt text

                    Which is interesting to know but I guess helps me figure out why they can't change their passwords.

                    And there you have it! Your GPO is preventing the exchange server from allowing the password to be changed any more often than 30 days. Come back in a month and it'll work. 🙂

                    So, I would leave the complexity in place, and set the Min Age to zero days. (All in the GPO on the DC)
                    Also, since my clients always put off changing their password until they can't..... I would implement this on your CAS/OWA server so they can change their passwords even after it has expired.

                    On the Client Access Server (CAS), click Start > Run and type regedit.exe and click OK.
                    Navigate to HKLM\SYSTEM\CurrentControlSet\Services\MSExchange OWA.
                    Right click the MSExchange OWA key and click New > DWord (32-bit).
                    The DWORD value name is ChangeExpiredPasswordEnabled and set the value to 1.

                    Note: The values accepted are 1 (or any non-zero value) for "Enabled" or 0 or blank / not present for "Disabled"

                    After you configure this DWORD value, you must reset IIS. The recommended method to reset IIS is to use IISReset /noforce from a command prompt.

                    Ref: http://blogs.technet.com/b/exchange/archive/2010/10/06/3411240.aspx

                    WLS-ITGuyW 1 Reply Last reply Reply Quote 3
                    • WLS-ITGuyW
                      WLS-ITGuy @JasGot
                      last edited by WLS-ITGuy

                      @JasGot said in GPO question:

                      @WLS-ITGuy said in GPO question:

                      @JasGot said in GPO question:

                      net accounts /domain

                      I went through and made sure no other GPOs have password settings. I have changed the default domain policy minimum age to 1 day

                      alt text

                      Saved, linked, enforced. Run GPUpdate /force and Checked on the DC:

                      alt text

                      Run GPUpdate /force and Checked on Domain joined PC:

                      alt text

                      Am I missing something?

                      JaredBuschJ 1 Reply Last reply Reply Quote 0
                      • JaredBuschJ
                        JaredBusch @WLS-ITGuy
                        last edited by

                        @WLS-ITGuy Never change the default domain policy. Like ever. It is simply asking for headaches later.

                        Make a new policy and apply it.

                        That aside, you changed a policy and it is not reflected. You have to have some other policy applying a setting.

                        1 Reply Last reply Reply Quote 1
                        • WLS-ITGuyW
                          WLS-ITGuy
                          last edited by

                          Well, Son of a Bitch!

                          alt text

                          GPO Status was set to disabled.

                          WLS-ITGuyW 1 Reply Last reply Reply Quote 0
                          • WLS-ITGuyW
                            WLS-ITGuy @WLS-ITGuy
                            last edited by WLS-ITGuy

                            @WLS-ITGuy

                            alt text

                            Thanks everyone for the assistance! I forgot that I had disabled the damn thing in the beginning of all this even though I told @dbeato that in a PM.

                            DashrenderD 1 Reply Last reply Reply Quote 1
                            • DashrenderD
                              Dashrender @WLS-ITGuy
                              last edited by

                              @WLS-ITGuy said in GPO question:

                              @WLS-ITGuy

                              alt text

                              Thanks everyone for the assistance! I forgot that I had disabled the damn thing in the beginning of all this even though I told @dbeato that in a PM.

                              I wonder what was setting it to 30 days then? Perhaps someone in the past set it to 30, then the GPO was disabled, and the setting just stuck until it was changed again and enabled.

                              1 Reply Last reply Reply Quote 0
                              • 1
                              • 2
                              • 2 / 2
                              • First post
                                Last post