Avatar of hypercube
hypercube
Flag for United States of America asked on

Changing Domain User password on demand not working

I helped an IT Admin change his password.
I went to the User in ADUC or AD Users and Computers tool on the DC and did this:

I reset the password with a random password and checked the box: The User must change the password at the next logon.
This did not change the password and the User wasn't prompted to change the password!

Next:
I reset the password with a known password and UNchecked the box: The User must change the password at the next logon.
This did change the password and the User wasn't prompted to change the password - just as expected.

Next:
The user tried to change his own password using ADUC and Access was Denied.

Does any of this ring a bell?
I did find this:
https://support.microsoft.com/en-us/help/832481/user-must-change-password-at-next-logon-check-box-is-unavailable
but it seems a somewhat different case.
Windows 10Windows Server 2019

Avatar of undefined
Last Comment
hypercube

8/22/2022 - Mon
SOLUTION
Hello There

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.
ASKER CERTIFIED SOLUTION
Alex

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.
hypercube

ASKER
I will try to address the sense of the questions in the responses:
The domain User has some limited domain admin privileges and is in a User OU with others of that type.
I've forced replication.  We do try to limit immediate actions to the same DC when making the changes and testing them.
I don't see that there is an "affected computer"...
The minimum password age is "0".
hypercube

ASKER
Thanks!!  Even with the great guidance, I never did find the smoking gun.  We just "re-did" it and got the new password entered.
Your help has saved me hundreds of hours of internet surfing.
fblack61