Solved

Is there a way to have Windows Server 2008 R2 do a mass notificatioin of a change in the password policy?

Posted on 2015-01-28
3
57 Views
Last Modified: 2015-02-12
We have set up a new password policy on a Windows Server 2008 R2 Domain. Part of that policy is to change there passwords after 90 days, but since all the users have existing passwords that are older than 90 days, the rule will initial right away, we think. We did a test today, and one user was not able to log into their workstation since the password policy had been applied to them. We had to go into ADUC and reset the password. Then the user could log into the Domain with the new password, but they were asked to change the password we had set. So, Is there a way to allow users to change the passwords on their own when the 90 day trigger hits, without the Domain admin having go into ADUC and reset each user? Thanks in advance. Joe W. \ Safe Harbor
0
Comment
Question by:zargf8ns
3 Comments
 
LVL 4

Expert Comment

by:Praveen Kumar Bonala
ID: 40576482
Hi,
It should ask to change password if it expires, please check the user properties weather user allowed to change password or not?
Please check following link to reset password of all users at a time:
http://www.petenetlive.com/KB/Article/0000497.htm
0
 
LVL 53

Accepted Solution

by:
Will Szymkowski earned 500 total points
ID: 40576483
This is a default mechanisum in Active Directory. When a users password expires they automatically get prompted to reset there password. The user can also change their own password at any time as well by press crtl+alt+del and choosing change password.

You can also use a 3rd party password self service product like SpecOps or Microsoft FIM. This will allow a user to also change there password if they have forgotten it or if they have locked their account out.

Will.
0
 
LVL 80

Expert Comment

by:David Johnson, CD, MVP
ID: 40576530
The usual rule is once an admin sets the password the user is prompted to change the password at next login (good security policy to keep as this way only the user knows their own password)
0

Featured Post

Is Your AD Toolbox Looking More Like a Toybox?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this article, we will see the basic design consideration while designing a Multi-tenant web application in a simple manner. Though, many frameworks are available in the market to develop a multi - tenant application, but do they provide data, cod…
This article shows how to deploy dynamic backgrounds to computers depending on the aspect ratio of display
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…

713 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question