[Last Call] Learn about multicloud storage options and how to improve your company's cloud strategy. Register Now

x
?
Solved

Domain user can't change password from their PC, don't have old password

Posted on 2010-11-30
6
Medium Priority
?
1,017 Views
Last Modified: 2012-05-10
I have a user who is joined to the domain and connected over a VPN connection. Their domain password has been changed and now their computer wants the new password. The problem is that the user does not know the old password.

So there are two problems/questions.

1. Can I find out what the old password was so I can update the desktop
2. When I update the desktop will it update the cached login information so she can log into the domain with the updated password?
0
Comment
Question by:ThorinO
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
6 Comments
 
LVL 7

Expert Comment

by:TheBDP
ID: 34241747
Can you set VPN to launch before windows? If so this would resolve this issue. If not can you RDP to the machine?
0
 
LVL 7

Expert Comment

by:Sappbrosts
ID: 34241766
is the desktop locked with the old password?  Was the user signed into the desktop when the domain password was changed?

If this is the case, just need to restart the PC and the user should be able to login with the new credentials
0
 
LVL 10

Author Comment

by:ThorinO
ID: 34241781
It is using the Windows based VPN client, I don't know if it can connect before logging in.

The user can log in with the old cached password, however it doesn't take that as the old one when trying to change the password.
0
Get free NFR key for Veeam Availability Suite 9.5

Veeam is happy to provide a free NFR license (1 year, 2 sockets) to all certified IT Pros. The license allows for the non-production use of Veeam Availability Suite v9.5 in your home lab, without any feature limitations. It works for both VMware and Hyper-V environments

 
LVL 10

Expert Comment

by:lobo797
ID: 34241815
You will not be able to find out the old password, but you can reset the password in Active Directory by 'right clicking' the user account and resetting the password.  

If the login screen is asking for an old password, then a new, go into the AD account by 'right clicking' the user and choosing properties.  On the account tab, unclick the item 'User must change password' and click item 'Password never expires'.  Reset the password to a temp one, log in, then back out.  In AD reverse the process and now the user will know the old password and can change to one they like.

All the best..
0
 
LVL 7

Accepted Solution

by:
TheBDP earned 2000 total points
ID: 34241823
Sorry I'm a little lost, can the user login and operate the PC at all, or is it forcing them to change their password as soon as they login even if they hit cancel? Set the password in AD to the same password as the users old password if you're able to get them onto the VPN. Have them lock the PC and then unlock with the same password while connected to the VPN.
0
 
LVL 66

Expert Comment

by:johnb6767
ID: 34243473
Log in with the cached password....
Navigate to C:\Window\system32\cmd.exe
Rt Click it>Run As... (might need to hold SHIFT+Click RunAs...
Select the user "Domain\Username"
Password is "NewPassword"

This will cache the new credentials on the machine, allowing access via the cached profile with the CURRENT password. No need for the old one.

This is all assuming that the cached profile fully works, and the connection to the VPN works.

Also, sometimes locking the screen while connected to VPN, and entering the new/current credentials will also work. Windows usually tells you it needs the new credentials, and to lock/unlock the workstation....
0

Featured Post

New feature and membership benefit!

New feature! Upgrade and increase expert visibility of your issues with Priority Questions.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article provides a convenient collection of links to Microsoft provided Security Patches for operating systems that have reached their End of Life support cycle. Included operating systems covered by this article are Windows XP,  Windows Server…
Let's recap what we learned from yesterday's Skyport Systems webinar.
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…

650 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question