Link to home
Start Free TrialLog in
Avatar of Cholo123
Cholo123

asked on

windows 2012 servers join to 2003 AD users cannot change password when it expires or when set to password most be change at next long

I have windows 2012 servers join to 2003 AD. Everything was working fine till i installed the latest windows updates around october/novemeber this year. Now my terminal server users cannot change their password when it expires or when i set "password most be change at next logon" in AD. Other windows 2012 servers that i have not install windows updates yet  are working fine. any help will be appreciated.


this articles below are having the same issue as me but with windows 8 machines join to 2003 AD.


https://community.spiceworks.com/topic/411135-windows-8-1-on-2003-ad-can-t-change-expired-password-on-login?page=1#entry-2775519

http://www.petri.co.il/forums/showthread.php?t=64760
Avatar of Sandesh Dubey
Sandesh Dubey
Flag of India image

It seems that  "Minimum password age"  is not set to 0 days which may be preventing the user to change password. check the same ands set it to zero and see how does it work.

See this similar thread Password Complixity Error:
http://social.technet.microsoft.com/Forums/windowsserver/en-US/43dcbc5f-e7e4-4aff-8d16-fa82a69690bb/password-complixity-error-while-change-password-through-owa 

By default in Win2003 domain you have one password policy applied at domain level in default domain policy you need to check the same.In case if you have multiple password policy then you need to check other policy too.
ASKER CERTIFIED SOLUTION
Avatar of Cholo123
Cholo123

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of Cholo123
Cholo123

ASKER

you are right windows update screw up the security. i rolled back to my previous VM configuration.