Jump to content

Recommended Posts

Posted

Hello

 

When users try and change passwords the computers are reporting that passwords do not meet the complexity requirements... but they are. Never seen this before, any suggestions where to start looking etc?

 

Domain: Server 2008 R2 function level.

 

Thanks

Posted

1.

 

Open Active Directory Users and Computers.

 

 

2.

 

In the console tree, right-click the domain or organizational unit that you want to set Group Policy for.

 

 

3.

 

Click Properties, and then click the Group Policy tab.

 

 

4.

 

Click an entry in Group Policy Object Links to select an existing Group Policy object (GPO), and then click Edit. You can also click New to create a new GPO, and then click Edit.

 

 

5.

 

In the console tree, click Password Policy (Group Policy Object [computer name] Policy/Computer Configuration/Windows Settings/Security Settings/Account Policies/Password Policy)

 

 

6.

 

In the details pane, right-click the policy setting that you want, and then click Properties.

 

 

7.

 

If you are defining this policy setting for the first time, select the Define this policy setting check box.

 

 

8.

 

Select the options that you want, and then click OK.

Posted

I had this the other day when users were trying to manually change their password through alt+ctrl+del. It wasn't the complexity (although the message claimed so) its the policy that says "password must be at least 30 days old before being allowed to change". Not sure if this is a newer password they are trying to change with your problem, but this does sound similar.

 

Its in group policy, default policy, Windows Settings, Security, Account, Password and in there.

Posted

This crops up here all the time, and it seems that AD will throw out passwords which aren't different enough to previous.

 

For instance someone with a previous password of chocolate2014 changing it to chocolate2015 would have it fail until they changed it to Choc0lat3@2015

 

My guidance to them is:

1, 8 characters or more

2, Uppercase letters

3, Lowercase letters

4, Numbers

5, Punctuation characters

6, No parts of a previous password.

 

This seems to work for most people.

Posted (edited)

Thanks for this folks.

 

I am seeing that when I reset a users password to say Password1 and force password change at next login the message is coming up about complexity etc.

 

Min password age is set to 1 day....

 

Most odd..... nothing has changed in my environment....

Edited by tech-man
Posted
It might be worth changing the policy on length of time before a previous password can be reused - as a test at least. You don't want them to be able to reuse passwords on alternate months, but it could identify where your issue is.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...