Jump to content

Recommended Posts

Posted

Ok then, what's the trick to this?

 

I've made a policy, which i've assigned to a security group that myself and the other two IT guys are in. However if i log off and back on it doesn't ask me to reset my password even though i know that it doesn't comply with the policy.

 

Do you have to manually tell users to change password on next logon? I was under the impression from responses i've had in the past that any password that doesn't comply will automatically prompt for change?

Posted

First I'd say are you using the 2012 route via ADAC? As we couldn't get the old GPO route to work anymore, and only seems to work once we moved to the ADAC style

 

In terms of the policy side, from my understanding it's about 50/50

 

Some don't apply till password change, e.g. complexity but others password age etc apply instantly

 

Steve

Posted
First I'd say are you using the 2012 route via ADAC? As we couldn't get the old GPO route to work anymore, and only seems to work once we moved to the ADAC style

 

In terms of the policy side, from my understanding it's about 50/50

 

Some don't apply till password change, e.g. complexity but others password age etc apply instantly

 

Steve

 

Yep using the 2012 route via ADAC. Domain is 2012R2 functional level too.

 

That's frustrating, i've changed minimum length to 8, and to require complexity, but no maximum age. I was hoping any staff members password that didn't comply with those settings would just need changing. Seems i may have been too presumptuous!

 

I've managed to persuade our SLT that this must be done, after a long time of one individual fighting back against this.

 

I plan on changing this for all staff on the 12th of Feb. So i guess I'm going to have to annoy everyone who's passwords already comply by forcing them to change too :(

Posted
I had the same issue when I set up our new policy - although ours does have a maximum age. In the end I reset the the password last changed attribute in AD for all staff and those that had changed it once, had to do it again. As it turned out no-one complained which must be a first!
Posted
Set the age to 28 days or whatever, so everyone will have to change their password on the 12th Feb, then remove the age limit afterwards. ET VOILA!
  • Thanks 2
  • 4 years later...
Posted
another gotcha is if you set a new password in ADDC then set the minimum age to 1 day (as is default) the user cannot manually change their password. This hit me in testing the policy. In reality you would just tick "user must change password at next logon"
Posted

More problems when I rolled this out! Some users getting prompted even though I didn't force it with "user must change password at next logon" other are not couldn't work out pattern until I realised that some accounts were set as "never expire".

 

Don't trust it now ant wondering if I should force it now but some users will have to change their password twice! Grr!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...