COMP2017 Server Administration Unit #8: Managing Users and Computers With GPO Name: - Soi
COMP2017 Server Administration Unit #8: Managing Users and Computers With GPO Name: - Soi
Requirements
Active Directory Installed on the odd numbers computer
The second server installed as a member server.
Configuration Summary
Textbook Reference
Role
Domain
lastname.local
Member Server
lastname.local
lastname.local
Procedure
Complete Project 8-1, as described.
Include a screenshot after part A step 6
A GPO named as PwdPoll was created and linked to the OU Marketing and Password
Policy Minimum Password Length was defined.
The following screenshot clearly indicates configuration of type of Auditing for the folder
ConfidentialFiles:
A GPO called Audit1 was created and linked to the OU Domain Controllers in domain
soi.local and in this GPO, the Audit Policy Audit Object Access was configured as shown
below:
To test the configured audit policies, users Lab8User1 and Lab8User2 were created and I
logged on with these users in my domain controller with domain soi.local and I accessed
the files in the folder ConfidentialFiles in the C-drive root. The following screenshots
illustrates the events created:
******************************
Review Questions
1) When you create a GPO to implement a new password policy, where must you link the
GPO to have the policy affect Active Directory domain accounts?
Ans: By creating and linking a GPO to implement a new password policy at
the domain-level, all Active Directory domain accounts will be affected. All
OUs that do not have the Block Inheritance setting enabled will inherit the
new password policy as well.
2) What does the Reset Account Lockout Counter After setting do?
Ans. The Reset Account Lockout Counter After setting resets the counter which
has locked the user account after certain number of failed logon attempts. The
reset is done after the number of minutes (as defined in this setting) elapsed.
8M
2M