To store fine-grained password policies, Windows Server 2008 includes two new object classes in the Active Directory Domain Services schema:
· Password Settings Container
· Password Settings
Password Settings Container is created by default under the System container in the domain. It stores the Password Settings objects (PSOs) for that domain. You cannot rename, move or delete this container.
A PSO has attributes for all the settings that can be defined in the Default Domain Policy (except Kerberos settings). These settings include attributes for the following password settings:
· Enforce password history
· Maximum password age
· Minimum password age
· Minimum password length
· Passwords must meet complexity requirements
· Store passwords using reversible encryption
These settings also include attributes for the following account lockout settings:
· Account lockout duration
· Account lockout threshold
· Reset account lockout after
In addition, a PSO has the following two new attributes:
· PSO link. This is a multivalued attribute that is linked to users and/or group objects.
· Precedence. This is an integer value that is used to resolve conflicts if multiple PSOs are applied to a user or group object.
These nine attributes are mustHave attributes. This means that you must define a value for each one. Settings from multiple PSOs cannot be merged.
Sunday, 9 September 2007
Subscribe to:
Post Comments (Atom)
0 comments:
Post a Comment