You need to create multiple password policies for usersin your domain

Your network consists of a single Active Directory domain.
The functional levelof the forestis Windows Server 2008 R2.
You need to create multiple password policies for usersin your domain.
What should you do?

Your network consists of a single Active Directory domain.
The functional levelof the forestis Windows Server 2008 R2.
You need to create multiple password policies for usersin your domain.
What should you do?

A.
From the Group Policy Management snap-in, create multiple Group Policy objects.

B.
From the Schema snap-in, create multiple class schema objects.

C.
From the ADSI Edit snap-in, create multiple Password Setting objects.

D.
From the Security Configuration Wizard, create multiple security policies.

Explanation:
Answer.From the ADSI Edit snap-in, create multiple Password Setting objects.
http://technet.microsoft.com/en-us/library/cc770842%28v=ws.10%29.aspx
AD DS Fine-Grained Password and Account Lockout Policy Step-by-Step Guide
..
In Windows Server 2008, you can use fine-grained password policies to specify multiple password policies and
apply different password restrictions and account lockout policies to different sets of users within asingle
domain.
..
To store fine-grained password policies, Windows Server 2008 includes two new object classes in the Active
Directory Domain Services (AD DS) schema:
Password Settings Container
Password Settings
The Password Settings Container (PSC) object class is created by default under the System container in the
domain. It stores the Password Settings objects (PSOs) for that domain. You cannot rename, move, or delete
this container.

Steps to configure fine-grained password and account lockout policies
When the group structure of your organization is defined and implemented, you can configure and apply finegrained password and account lockout policies to users and global security groups. Configuring fine-grained
password and account lockout policies involves the following steps:
Step 1: Create a PSO
Step 2: Apply PSOs to Users and Global SecurityGroups
Step 3: Manage a PSO
Step 4: View a Resultant PSO for a User or a Global Security Group
http://technet.microsoft.com/en-us/library/cc754461%28v=ws.10%29.aspx
Step 1: Create a PSO
You can create Password Settings objects (PSOs):
Creating a PSO using the Active Directory module for Windows PowerShell
Creating a PSO using ADSI Edit
Creating a PSO using ldifde



Leave a Reply 0

Your email address will not be published. Required fields are marked *