官术网_书友最值得收藏!

Default Domain Policy

As you have probably noticed while following along with our lab build so far, there is this thing hanging out inside GPMC called the Default Domain Policy. This is a GPO that always exists by default in a fresh domain implementation. In fact, I have never seen an environment where this policy did not exist, so it is not a common practice for anyone to remove or delete it.

The Default Domain Policy contains a handful of security-related settings. The most important part to understand about this default policy is that it applies to everyone: a users on all domain-joined systems. Any settings you plug into the Default Domain Policy will roll out on a very large scale, which could cause you a lot of grief if not done properly. So it is recommended to basically leave this GPO alone unless you are absolutely sure about the settings that you are going to use within it.

Oftentimes, what I see in smaller environments is that the IT staff (sometimes just one person) has made a little bit of use of the Default Domain Policy, perhaps modifying the password policy as we will be doing in just a few pages. This probably happens because there are plenty of blog posts and how-tos out there that guide an IT administrator through modifying the corporate password policy to make it stronger, and the easiest way to show this procedure is through a simple edit of the default policy. Often this GPO is the extent of how Group Policy as a whole is used in these smaller businesses, which is unfortunate because of how immensely powerful Group Policy can be when used more extensively. As you can see in the following screenshot, there are not many settings inside the Default Domain Policy, and most of them are related to user passwords. If you have ever wondered why or how complex passwords are required right off the bat, even in a brand-spanking-new installation of Active Directory, this GPO is your answer:

Since we are talking about a policy that applies to everyone, let's explore the reason why the Default Domain Policy applies to everyone.

主站蜘蛛池模板: 临沧市| 宁乡县| 迭部县| 新河县| 如皋市| 扬州市| 固安县| 红河县| 莱州市| 大名县| 花垣县| 休宁县| 玛多县| 神木县| 丹棱县| 大渡口区| 壶关县| 湟中县| 天峨县| 星子县| 农安县| 屏东县| 普兰店市| 丰都县| 沁源县| 辽阳市| 新田县| 清远市| 金堂县| 靖西县| 晋城| 江津市| 合山市| 潜山县| 阿鲁科尔沁旗| 应城市| 东宁县| 阿尔山市| 高平市| 韶关市| 灵石县|