Default Domain Policy with password policies, can I block inheritance of these policies from a specific OU ?

Andrea 1 Reputation point
2022-10-14T14:09:56.957+00:00

Hi all,

I'm have trouble configuring Kiosk on Intune. I get always an error about passwords complexity with autologon.

So I put my user and computer inside an OU where I checked Block Inheritance. Now inside this OU (that I called TEST) there aren't GPOs applied. Nothing.
But I continue to receive errors about passwords complexity.

In our domain we have also set Policies about passwords complexity inside Default Domain Policy GPO.

Now I'm thinking that Default Domain Policy GPO is applied to mine OU TEST also if I Block Inheritance on this OU. Can it be ? If yes, where can I find a Microsoft article where this thing is explained ?

And now, how can I solve this deadlock ? Should I create a new GPO only for passwords complexity that I will apply to my DC and remove all passwords policies from Default Domain Policy ?
If I do something like that will I solve? So new gpo for passwords complexity will not applied if I check Block Inheritance ?

or is there another way ?

Thanks who will reply.

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Microsoft Security | Intune | Other
Community Center | Not monitored
{count} votes

1 answer

Sort by: Most helpful
  1. Gary Reynolds 9,621 Reputation points
    2022-10-17T09:49:30.327+00:00

    Hi @Andrea

    Have a read of this answer to the same question, which explains the password policy is applied at the domain level and not at the ou level. The best option would be apply a fine grain password policy to the users.

    https://learn.microsoft.com/en-us/answers/questions/179808/how-to-override-the-default-domain-password-policy.html

    Gary.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.