Azure AD Synchronized Users with Password Sync are unable to change password

nav2567
nav2567 used Ask the Experts™
on
Hi,

Our AD connect syncs on-premises AD account passwords to Office 365.  

I go to my AD and reset password for a user and check "user must change password at next logon".  

The user logins, enter the password I give him and enter his own password.  He is getting this error:

Your organization doesn't allow you to update your password on this site. Please update it according to the method recommended by your organization, or ask your admin if you need help.

I am reading this link but dont quite get it: http://www.edutech.me.uk/microsoft/identity-and-access-management/authentication/azure-ad-synchronized-users-with-password-sync-are-unable-to-change-password/

Please advise what I need to do to allow the user to check his password.

Thanks.
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
Senior Systems Admin
Top Expert 2010
Commented:
Unless you have Azure AD Premium and Password Write-back enabled, you can't reset passwords for synchronized accounts in any part of Azure or O365, even if the user is set to change the password after login. They have to log in to a Domain-joined computer, reset their password, wait for the password sync to occur following their reset, then log in.

If, however, your accounts had been created in O365 (and not synced), the password reset option would function normally. Ditto for if you have Azure AD Premium licenses assigned to the users and have configured Azure AD to allow password resets in the cloud (it's actually a really confusing and complex process).

As a side note, I think it's pretty stupid that MS charges $4 per user (or whatever) for Azure AD Premium just to allow people to change their own passwords in the cloud, but that's where they're going with it, and there isn't anything we can do about it. Unless you want to fork over more money for the feature, you'll have to manage passwords in AD only.

Author

Commented:
Adam, thank you, thank you!!!

Author

Commented:
Adam, thank you, thank you!!!

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial