Maybe someone can help me out here. I applied a GPO to the domain that has an account lockout threshold of 3. Then I applied a GPO to a particular OU that has NO account lockout. Whenever I try to login with an account in that OU, I get locked out after 3 invalids. I thought OU lvl GPOs were supposed to override domain lvl GPOs ? Is that not the case with account lockout policies ?


