Solved

trouble changing passwords - sometimes

Posted on 2002-07-12
6
836 Views
Last Modified: 2010-04-13

Every Blue moon or two, I get this message:





---------------------------
Active Directory
---------------------------
The password for George S cannot be set due to insufficient privileges. Windows will attempt to disable this account. If this attempt fails, the account will become a security risk. Contact an administrator as soon as possible to repair this. Before this user can log on, the password should be set, and the account must be enabled.
---------------------------
OK  
---------------------------






I can change the password if I try later, but its a pain the rump. Any thoughts? This only seems t happen when I try on a user that was just created.
0
Comment
Question by:jg733
  • 3
  • 2
6 Comments
 
LVL 17

Expert Comment

by:mikecr
ID: 7149632
Do you have an AD policy for changing passwords? How long after you create the account are you attempting to change the password? Where is the Global Catalog server located at on your network, at your location or a different location?
0
 
LVL 12

Expert Comment

by:guidway
ID: 7149650
0
 
LVL 1

Author Comment

by:jg733
ID: 7149714
guidway. Thanks, but I saw that too. It didn't help.

Mikecr, I have some policies set. What specifically are you asking for?

Immediately after the change is when I try to change it.

The GC is in the same site.


Thanks,

Jeff
0
Ransomware-A Revenue Bonanza for Service Providers

Ransomware – malware that gets on your customers’ computers, encrypts their data, and extorts a hefty ransom for the decryption keys – is a surging new threat.  The purpose of this eBook is to educate the reader about ransomware attacks.

 
LVL 17

Expert Comment

by:mikecr
ID: 7149755
That's probably part of your problem. Whenever you create the account and password the first time and then you attempt to change the password immediately thereafter, the machine needs to query the GC first before issuing the password change dialog box. At this point AD has not been updated completely and the changes have not been made yet to the GC. If you wait about 30 minutes you should be able to change the password normally. This has to do with replication between domain controllers within the domain. You can fix this by shortening the amount of time between replications of domain controllers.
0
 
LVL 1

Author Comment

by:jg733
ID: 7150049
Mikecr, I don't think that is it - because of some information I should have said:

When what you are describing happens, I get an informational message stating (paraphrasing) The account you are modifying was recently created or has not replicated, try agin later, blah blah


since the machine is in the same site as the GC, both logically and physically, I thought that the update would be near instant. However, I'm not that confident about this...

However, I will look more into the health of my GC server...
0
 
LVL 17

Accepted Solution

by:
mikecr earned 75 total points
ID: 7157453
You GC gets queried every time a user logs into the network looking for account information, if it does not exist, you will get an error message similiar to the one that your getting. Whenever an account is created, the domain controllers replicate between themselves on a timed basis and it is not instantaneous. It can take a few minutes for all changes to become apparent.
0

Featured Post

Complete VMware vSphere® ESX(i) & Hyper-V Backup

Capture your entire system, including the host, with patented disk imaging integrated with VMware VADP / Microsoft VSS and RCT. RTOs is as low as 15 seconds with Acronis Active Restore™. You can enjoy unlimited P2V/V2V migrations from any source (even from a different hypervisor)

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
This article explains the steps required to use the default Photos screensaver to display branding/corporate images
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…

828 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question