Solved

Server 2008 R2 Active Directory

Posted on 2013-06-11
4
317 Views
Last Modified: 2013-06-11
I have an internal application which links with AD for the password and I'm finding that when the password expires in the middle of the day this causes problems. Is there a way to always make the password expire at midnight regardless of when the user changes it.  Say they set it today ( 6/11/2013 ) at 11:05am and the system then sets the password to expire three months down the road at 9/11/2013 at 11:05am ..... I would prefer the password actually be set to expire at 9/11/2013 at midnight .......

What I'm finding is the users wait till the last minute to change their password and then they can't log into our internal app or exchagne in the middle of the day because  the system has expired their password in the middle of the day ........  

THanks .....

Joel T Brown
0
Comment
Question by:jtbrown1111
  • 2
4 Comments
 
LVL 5

Expert Comment

by:peter197911
ID: 39239492
I don't have a proper on your question.

Part of the problem:  Users should change their password.
I think you can use this example to the company to show the importance of changing your password when windows asks for it.

And the users will have the problems theirselves....
0
 

Author Comment

by:jtbrown1111
ID: 39239539
@ peter197911 ,  I would totally agree with you but as a single support for 110 staff of which 22 are doctors its sometimes easier to put things in place that make " MY " life easier when you can't force others to do what they should ......        

THanks ....

Joel
0
 
LVL 5

Accepted Solution

by:
peter197911 earned 500 total points
ID: 39239583
Copy paste from another site:

Windows simply doesn't support the concept of a "password expiry time" that applies globally. You also cannot set the time, except to say it is expired now, or that it was just changed. However, what you could do is write a script using command-line AD tools or powershell that runs nightly: it can query AD for users with passwords due to expire in less than 24h (pwdLastSet is older than one day less than your password max age days), and set it to -1 (the password is expired). This would avoid extending password life unintentionally, and also avoid midday password expiration.

So, for example on Monday, check what passwords are going to expire in the next 5 days.
Set the expire status on  "-1".

Users will be asked in the morning that they have to change their password.

Run this cript once per week and your done...
0
 
LVL 57

Expert Comment

by:Mike Kline
ID: 39239600
You won't be able to do this as you can't modify pwdlastset.  I feel your pain and have some possible workarounds

1. Use finegrained passwords (FGPP) to set the Dr/VIP/biggest complainers to expire less frequently   Maybe if your policy is every 90 days use a FGPP for 180 days for them

2. This way is not recommended but set their passwords to never expire on their AD account...again not recommended.

Thanks

Mike
0

Featured Post

Microsoft Certification Exam 74-409

Veeam® is happy to provide the Microsoft community with a study guide prepared by MVP and MCT, Orin Thomas. This guide will take you through each of the exam objectives, helping you to prepare for and pass the examination.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Introduction You may have a need to setup a group of users to allow local administrative access on workstations.  In a domain environment this can easily be achieved with Restricted Groups and Group Policies. This article will demonstrate how to…
Possible fixes for Windows 7 and Windows Server 2008 updating problem. Solutions mentioned are from Microsoft themselves. I started a case with them from our Microsoft Silver Partner option to open a case and get direct support from Microsoft. If s…
This tutorial will give a an overview on how to deploy remote agents in Backup Exec 2012 to new servers. Click on the Backup Exec button in the upper left corner. From here, are global settings for the application such as connecting to a remote Back…
This tutorial will walk an individual through the steps necessary to enable the VMware\Hyper-V licensed feature of Backup Exec 2012. In addition, how to add a VMware server and configure a backup job. The first step is to acquire the necessary licen…

911 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

25 Experts available now in Live!

Get 1:1 Help Now