Solved

User cannot change password

Posted on 2009-04-08
9
293 Views
Last Modified: 2012-05-06
We have an issue where in AD the "user cannot change password" tick box is not staying ticked.

Any ideas?
0
Comment
Question by:Alex-Kay
  • 4
  • 3
  • 2
9 Comments
 
LVL 1

Expert Comment

by:jnicpon
ID: 24098645
Check the GPOs that are affecting the parent container of the user object. Ensure that there is no policy directly affecting the object.
0
 
LVL 1

Author Comment

by:Alex-Kay
ID: 24098669
Can you be more specific about what to look for?
0
 
LVL 23

Expert Comment

by:Stacy Spear
ID: 24117687
gpresult /USER domain\user /Z
0
 
LVL 23

Expert Comment

by:Stacy Spear
ID: 24117753
Oops, it will show what policies are set for the user. Nice thing about the Z switch is that it will show if the same parameter is set in multiple places.
0
 
LVL 1

Author Comment

by:Alex-Kay
ID: 24135763
Any idea what we would need to look for in the output of that, that would affect the "user cannot change password" policy.

Thanks
0
 
LVL 23

Expert Comment

by:Stacy Spear
ID: 24139095
0
 
LVL 1

Author Comment

by:Alex-Kay
ID: 24139113
Please see attached two results from two users the 1st is being affected the 2nd is not, I have highlighted the only differences that I can see.

Would these affect?
userresults1.docx
useresults2.docx
0
 
LVL 1

Accepted Solution

by:
jnicpon earned 125 total points
ID: 24140140
Looked at your attachments. I would venture to say you're not going to find many clues in the policy test results. You'll need to examine the details of each policy that contains security elements, as well as examining security that is set on parent OU of the accounts, as well as on the individual user objects. This can be done via the User & Computers AD console by enabling advanced view. Right-click properties/Security Tab may shed some light on this.
0
 
LVL 23

Assisted Solution

by:Stacy Spear
Stacy Spear earned 125 total points
ID: 24140278
Agreed. You will have to go into GPO management and look at each one if there isn't documentation on the GPOs. Limiting who has access to GPOs and even the number of domain admins is always best. GPOs can be so complex, they should, I feel that they must, be documented.
0

Join & Write a Comment

Companies that have implemented Microsoft’s Active Directory need to ensure that the Active Directory is configured and operating properly. If there are issues found and not resolved, it eventually leads the components to fail or stop working and fi…
Disabling the Directory Sync Service Account in Office 365 will stop directory synchronization from working.
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…

747 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now