[2 days left] What’s wrong with your cloud strategy? Learn why multicloud solutions matter with Nimble Storage.Register Now

x
?
Solved

Active Directory Password Never Expires

Posted on 2013-11-11
12
Medium Priority
?
1,459 Views
Last Modified: 2013-11-12
I have Default Domain policy maximum age 90 days
the Enforced is set "NO"

I have an AD account that has password never expires. However regardless of that the account has expired.

I am not sure why ?

Any help on how to make th password never expires differently than what I have done?

Thanks.
0
Comment
Question by:jskfan
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 7
  • 2
  • 2
  • +1
12 Comments
 
LVL 34

Assisted Solution

by:Paul MacDonald
Paul MacDonald earned 800 total points
ID: 39639732
Are you a Domain Admin?  Because that would do it.
0
 

Author Comment

by:jskfan
ID: 39639739
yes I am domain Admin.

the account that get expired is a service account...it was set to never Expires but it expired.
0
 

Author Comment

by:jskfan
ID: 39639745
the service account is member of domain users only
0
Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
LVL 35

Assisted Solution

by:Seth Simmons
Seth Simmons earned 400 total points
ID: 39639777
I have an AD account that has password never expires. However regardless of that the account has expired.

I am not sure why ?

doesn't matter what the password policy is - you said the account itself expired
0
 

Author Comment

by:jskfan
ID: 39639789
but it is set to never expires
0
 
LVL 34

Assisted Solution

by:Paul MacDonald
Paul MacDonald earned 800 total points
ID: 39639790
Sorry, I presumed you meant *your* account never expired.

Is it possible the service account exists in a container where the password policy doesn't apply?  Or is is possible the service account doesn't have permissions to Read the policy?
0
 

Author Comment

by:jskfan
ID: 39639802
a colleague of mine ran a tool it gave him the password status:
Max password age for svcaccount1 is 90 days
current password age is 91 days 5  hours 45 min
password remains valid for : 44444 days  4 hours 10 min
0
 

Author Comment

by:jskfan
ID: 39639814
the account is set to "Never expires", so the only way it will expire if the Default domain policy was Enforced, but it is not enforced.
I am not sure what made it expire
0
 
LVL 38

Assisted Solution

by:Hypercat (Deb)
Hypercat (Deb) earned 800 total points
ID: 39639886
I'm a little confused - what is expiring, the account or the account's password?  These are two different settings.  You can set either one or both of them to never expire. If the password policy is set to require passwords to be changed every 90 days, and you want the account to have a non-expiring password, then you need to check the box in the AD account properties "Password never expires." Is that the box you have checked?
0
 

Author Comment

by:jskfan
ID: 39640140
<<<If the password policy is set to require passwords to be changed every 90 days, and you want the account to have a non-expiring password, then you need to check the box in the AD account properties "Password never expires." Is that the box you have checked? >>>

Correct..That 's how it was configured.

but for some reason the service account password got expired and the Application service did not run
0
 
LVL 38

Accepted Solution

by:
Hypercat (Deb) earned 800 total points
ID: 39641713
Did the service account get locked out?  That is really strange and I've never seen it happen.  Anyway, I'd be inclined to create a new service account, making sure the "Password never expires" box is checked when you create the account, and then set that service to start using the new account.  Also re-check the password policy in the group policy for the OU where the account exists and make sure there aren't any other settings being applied that might override this setting. I normally create a separate OU for administrative and service accounts and set the OU to block inheritance so that other domain policies don't get applied by mistake.
0
 

Author Closing Comment

by:jskfan
ID: 39642230
Thanks
0

Featured Post

Fill in the form and get your FREE NFR key NOW!

Veeam® is happy to provide a FREE NFR server license to certified engineers, trainers, and bloggers.  It allows for the non‑production use of Veeam Agent for Microsoft Windows. This license is valid for five workstations and two servers.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This process allows computer passwords to be managed and secured without using LAPS. This is an improvement on an existing process, enhanced to store password encrypted, instead of clear-text files within SQL
In the absence of a fully-fledged GPO Management product like AGPM, the script in this article will provide you with a simple way to watch the domain (or a select OU) for GPOs changes and automatically take backups when policies are added, removed o…
To efficiently enable the rotation of USB drives for backups, storage pools need to be created. This way no matter which USB drive is installed, the backups will successfully write without any administrative intervention. Multiple USB devices need t…
This tutorial will show how to configure a new Backup Exec 2012 server and move an existing database to that server with the use of the BEUtility. Install Backup Exec 2012 on the new server and apply all of the latest hotfixes and service packs. The…

649 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question