There are three possible settings for NT/2000 policies: enabled (checked), un-defined (greyed out) and disabled (white, no check-mark). By leaving a policy setting undefined, you are effectively telling the workstation, "Do whatever it is you usually do, this setting doesn't apply to you." If you wish to explicitly state, "Do not use any account lockout settings," explicitly un-check the appropriate setting so that the box next to it is white, not grey. This will override any existing or conflicting settings on the workstation.
Dig Deeper on Microsoft Active Directory Tools and Troubleshooting
Related Q&A from Laura E. Hunter
Active Directory expert Laura E. Hunter offers some advice for changing the IP addresses of domain controllers.continue reading
A Windows administrator moving from Windows Server 2003 to Windows Server 2003 R2 wants to perform a restore of a previous server to a new one ...continue reading
An admin needs to grant user access rights for those needing to traverse directory trees. Our server management expert explains how to use Group ...continue reading
Have a question for an expert?
Please add a title for your question
Get answers from a TechTarget expert on whatever's puzzling you.