[2 days left] What’s wrong with your cloud strategy? Learn why multicloud solutions matter with Nimble Storage.Register Now

x
?
Solved

User cannot change password

Posted on 2009-04-08
9
Medium Priority
?
335 Views
Last Modified: 2012-05-06
We have an issue where in AD the "user cannot change password" tick box is not staying ticked.

Any ideas?
0
Comment
Question by:Alex-Kay
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
  • 2
9 Comments
 
LVL 1

Expert Comment

by:jnicpon
ID: 24098645
Check the GPOs that are affecting the parent container of the user object. Ensure that there is no policy directly affecting the object.
0
 
LVL 1

Author Comment

by:Alex-Kay
ID: 24098669
Can you be more specific about what to look for?
0
 
LVL 23

Expert Comment

by:Stacy Spear
ID: 24117687
gpresult /USER domain\user /Z
0
VIDEO: THE CONCERTO CLOUD FOR HEALTHCARE

Modern healthcare requires a modern cloud. View this brief video to understand how the Concerto Cloud for Healthcare can help your organization.

 
LVL 23

Expert Comment

by:Stacy Spear
ID: 24117753
Oops, it will show what policies are set for the user. Nice thing about the Z switch is that it will show if the same parameter is set in multiple places.
0
 
LVL 1

Author Comment

by:Alex-Kay
ID: 24135763
Any idea what we would need to look for in the output of that, that would affect the "user cannot change password" policy.

Thanks
0
 
LVL 23

Expert Comment

by:Stacy Spear
ID: 24139095
0
 
LVL 1

Author Comment

by:Alex-Kay
ID: 24139113
Please see attached two results from two users the 1st is being affected the 2nd is not, I have highlighted the only differences that I can see.

Would these affect?
userresults1.docx
useresults2.docx
0
 
LVL 1

Accepted Solution

by:
jnicpon earned 375 total points
ID: 24140140
Looked at your attachments. I would venture to say you're not going to find many clues in the policy test results. You'll need to examine the details of each policy that contains security elements, as well as examining security that is set on parent OU of the accounts, as well as on the individual user objects. This can be done via the User & Computers AD console by enabling advanced view. Right-click properties/Security Tab may shed some light on this.
0
 
LVL 23

Assisted Solution

by:Stacy Spear
Stacy Spear earned 375 total points
ID: 24140278
Agreed. You will have to go into GPO management and look at each one if there isn't documentation on the GPOs. Limiting who has access to GPOs and even the number of domain admins is always best. GPOs can be so complex, they should, I feel that they must, be documented.
0

Featured Post

Fill in the form and get your FREE NFR key NOW!

Veeam® is happy to provide a FREE NFR server license to certified engineers, trainers, and bloggers.  It allows for the non‑production use of Veeam Agent for Microsoft Windows. This license is valid for five workstations and two servers.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

After seeing many questions for JRNL_WRAP_ERROR for replication failure, I thought it would be useful to write this article.
This process allows computer passwords to be managed and secured without using LAPS. This is an improvement on an existing process, enhanced to store password encrypted, instead of clear-text files within SQL
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
Sometimes it takes a new vantage point, apart from our everyday security practices, to truly see our Active Directory (AD) vulnerabilities. We get used to implementing the same techniques and checking the same areas for a breach. This pattern can re…

649 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question