官术网_书友最值得收藏!

Default Domain Policy

As you have probably noticed while following along with our lab build so far, there is this thing hanging out inside GPMC called the Default Domain Policy. This is a GPO that always exists by default in a fresh domain implementation. In fact, I have never seen an environment where this policy did not exist, so it is not a common practice for anyone to remove or delete it.

The Default Domain Policy contains a handful of security-related settings. The most important part to understand about this default policy is that it applies to everyone: a users on all domain-joined systems. Any settings you plug into the Default Domain Policy will roll out on a very large scale, which could cause you a lot of grief if not done properly. So it is recommended to basically leave this GPO alone unless you are absolutely sure about the settings that you are going to use within it.

Oftentimes, what I see in smaller environments is that the IT staff (sometimes just one person) has made a little bit of use of the Default Domain Policy, perhaps modifying the password policy as we will be doing in just a few pages. This probably happens because there are plenty of blog posts and how-tos out there that guide an IT administrator through modifying the corporate password policy to make it stronger, and the easiest way to show this procedure is through a simple edit of the default policy. Often this GPO is the extent of how Group Policy as a whole is used in these smaller businesses, which is unfortunate because of how immensely powerful Group Policy can be when used more extensively. As you can see in the following screenshot, there are not many settings inside the Default Domain Policy, and most of them are related to user passwords. If you have ever wondered why or how complex passwords are required right off the bat, even in a brand-spanking-new installation of Active Directory, this GPO is your answer:

Since we are talking about a policy that applies to everyone, let's explore the reason why the Default Domain Policy applies to everyone.

主站蜘蛛池模板: 陆河县| 宁乡县| 洛川县| 定陶县| 阿克苏市| 大足县| 叙永县| 阿拉善右旗| 车险| 清苑县| 巫山县| 墨脱县| 北流市| 泾阳县| 通海县| 田东县| 通州市| 电白县| 左权县| 汉川市| 九龙县| 邮箱| 兴国县| 泽州县| 榕江县| 辉县市| 湄潭县| 张掖市| 汾西县| 财经| 巴东县| 丁青县| 长白| 海门市| 宝坻区| 行唐县| 通化市| 三河市| 五寨县| 正宁县| 平果县|