How can I verify the target domain password policies? (NETIQKB28255)

  • 7728255
  • 02-Feb-2007
  • 05-Mar-2008

Resolution

goal
How can I verify the target domain password policies?

fact
Domain Migration Administrator 7.x

fact
Domain Migration Administrator 6.x

fix

You can use the Microsoft MMC Security Configuration and Analysis snap-in to help troubleshoot whether or not a security policy is causing the password copy process to fail.

FROM A DC ONLY:

  1. Click Start --> Run --> type in "MMC"
  2. Click Console --> Add/Removesnap-in
  3. Click Add
  4. Choose Security Configuration and Analysis
  5. Click Add
  6. Click Close
  7. Click OK
  8. Click on Security Configuration and Analysis in the left hand pane
  9. Right Click --> Open database
  10. Type a name for a new database
  11. Click Open
  12. Select Basic dc
  13. Click Open (If you receive an error after clicking open, click OK on the error and ignore it)
  14. Click on Security Configuration and Analysis in the left hand pane
  15. Right Click --> Analyze computer now
  16. Click OK (to log path)
  17. Expand tree to expose 'Password policy' (Security Configuration and Analysis --> Account Policies --> Password Policy)
  18. Examine the policy settings

To Make Changes:

  1. Double click on policy (Password History)
  2. Check the box for 'Define this policy in database'
  3. Enter value (0 passwords remembered) - make note of previous value
  4. Click OK
  5. Right click on Security Configuration and Analysis
  6. Select Configure computer now
  7. Click OK (to log path)
  8. Right click on Security Configuration and Analysis
  9. Click Analyze computer
  10. Verify policy was changed

To Return to previous value:

  1. Double click on policy setting
  2. Change the value back to the original setting
  3. Click Configure computer now
  4. Click Analyze
  5. Double click on policy
  6. Clear checkbox for 'define this setting'


Additional Information

Formerly known as NETIQKB28255