Solved

One-time password change for all users?

Posted on 2012-04-09
6
465 Views
Last Modified: 2012-04-10
I'd like to enforce a one-time password changes for all users in AD.  The problem is, we have some users that work once a month and only use OWA.  So, if I set passwords to expire in 30 days, then some users may have to change their password twice.  If the OWA users don't change before expiration, they are locked out which causes IT major inconvenience.

Does anyone have a strategy they can suggest?
0
Comment
Question by:sbumpas
6 Comments
 
LVL 22

Expert Comment

by:Joseph Moody
ID: 37824777
If I understand your question correctly, you should be about to right click all of your users in an OU - select properties and then account. Then check user must change password at next logon.

I would test this on a small set of users first.
0
 
LVL 17

Expert Comment

by:pjam
ID: 37824855
What jmoody says is what we do when we migrate a site from one domain to a another
0
 

Author Comment

by:sbumpas
ID: 37825054
The problem with that strategy is OWA users are locked out until their passwords are changed via AD login.  Some users rely exclusively on OWA, so we would get dozens of calls to unlock accounts.
0
Best Practices: Disaster Recovery Testing

Besides backup, any IT division should have a disaster recovery plan. You will find a few tips below relating to the development of such a plan and to what issues one should pay special attention in the course of backup planning.

 
LVL 11

Expert Comment

by:BillBondo
ID: 37825075
perhaps make the owa people a separate group with longer password changes
0
 

Author Comment

by:sbumpas
ID: 37825088
Well this would be a one-time change, so I'm not sure how a longer interval would help?
0
 
LVL 1

Accepted Solution

by:
Columbia Energy earned 500 total points
ID: 37825682
There's no clean way to do what you ask.  Exclude the OWA users from the forced password change.  If this is OWA 2007 or later, email those users and instruct them to change their passwords and provide instructions on how to do so (via OWA).

It's not perfect, but it should reduce the headaches.
0

Featured Post

Best Practices: Disaster Recovery Testing

Besides backup, any IT division should have a disaster recovery plan. You will find a few tips below relating to the development of such a plan and to what issues one should pay special attention in the course of backup planning.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

In this article, I am going to show you how to simulate a multi-site Lab environment on a single Hyper-V host. I use this method successfully in my own lab to simulate three fully routed global AD Sites on a Windows 10 Hyper-V host.
This article outlines the process to identify and resolve account lockout in an Active Directory environment.
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…

810 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question