Issue with Mac users AD password resetting

IT Guy
IT Guy used Ask the Experts™
on
Have been battling this issue for over a year now, here is my setup

i have mac AD users, their macbooks are joined to AD with a software called Centrify, every 90 Days our AD users need to reset their passwords. the Centrify app prompts them to reset their AD password however when they enter their old and new password the Centrify app prompts them that they have not reach their complexity requirements require for their password. Now AD actually takes the password but the user thinks it does not and now the user cannot login to their macbook

the workaround for me is to remove the user from the domain then re-add the macbook

any ideas what this could be.
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
AmitIT Architect
Distinguished Expert 2017

Commented:
Looks like you have password complexity mismatch, between you AD and centrify server. Do you have password complexity enabled in AD?

Author

Commented:
yes password complexity is enabled on AD but did not find in centify policy.
AmitIT Architect
Distinguished Expert 2017

Commented:
Just check this KB for centrify: https://docs.centrify.com/Content/CoreServices/UsersRoles/PasswrdComplexReq.htm

and this one for AD: https://docs.microsoft.com/en-us/windows/security/threat-protection/security-policy-settings/password-must-meet-complexity-requirements

Better you disable complexity within AD and let centrify force the complexity. I have seen this issue with few of my client and solution we used, to disable from AD end. However, you check with your team, before doing anything or vendor might be able to answer.
Ensure you’re charging the right price for your IT

Do you wonder if your IT business is truly profitable or if you should raise your prices? Learn how to calculate your overhead burden using our free interactive tool and use it to determine the right price for your IT services. Start calculating Now!

Author

Commented:
i have directmanage deployment manager and Access manager, i could not find any core services policies listed under those, maybe i need to install another software on my server
AmitIT Architect
Distinguished Expert 2017

Commented:
I advise you to check with Centrify vendor, they might give more details and solution for your issue.

Author

Commented:
yea - i worked with them on this for about a year with no avail solution, trying to download their latest software Centrify Infrastructure Services 18.8 for 64-bit Windows

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial