mrbios Posted January 14, 2016 Posted January 14, 2016 Ok then, what's the trick to this? I've made a policy, which i've assigned to a security group that myself and the other two IT guys are in. However if i log off and back on it doesn't ask me to reset my password even though i know that it doesn't comply with the policy. Do you have to manually tell users to change password on next logon? I was under the impression from responses i've had in the past that any password that doesn't comply will automatically prompt for change?
Steve21 Posted January 14, 2016 Posted January 14, 2016 First I'd say are you using the 2012 route via ADAC? As we couldn't get the old GPO route to work anymore, and only seems to work once we moved to the ADAC style In terms of the policy side, from my understanding it's about 50/50 Some don't apply till password change, e.g. complexity but others password age etc apply instantly Steve
mrbios Posted January 14, 2016 Author Posted January 14, 2016 First I'd say are you using the 2012 route via ADAC? As we couldn't get the old GPO route to work anymore, and only seems to work once we moved to the ADAC style In terms of the policy side, from my understanding it's about 50/50 Some don't apply till password change, e.g. complexity but others password age etc apply instantly Steve Yep using the 2012 route via ADAC. Domain is 2012R2 functional level too. That's frustrating, i've changed minimum length to 8, and to require complexity, but no maximum age. I was hoping any staff members password that didn't comply with those settings would just need changing. Seems i may have been too presumptuous! I've managed to persuade our SLT that this must be done, after a long time of one individual fighting back against this. I plan on changing this for all staff on the 12th of Feb. So i guess I'm going to have to annoy everyone who's passwords already comply by forcing them to change too
truebluesteve Posted January 14, 2016 Posted January 14, 2016 I had the same issue when I set up our new policy - although ours does have a maximum age. In the end I reset the the password last changed attribute in AD for all staff and those that had changed it once, had to do it again. As it turned out no-one complained which must be a first!
Joanne Posted January 14, 2016 Posted January 14, 2016 Set the age to 28 days or whatever, so everyone will have to change their password on the 12th Feb, then remove the age limit afterwards. ET VOILA! 2
Alis_Klar Posted February 11, 2020 Posted February 11, 2020 another gotcha is if you set a new password in ADDC then set the minimum age to 1 day (as is default) the user cannot manually change their password. This hit me in testing the policy. In reality you would just tick "user must change password at next logon"
Alis_Klar Posted February 12, 2020 Posted February 12, 2020 More problems when I rolled this out! Some users getting prompted even though I didn't force it with "user must change password at next logon" other are not couldn't work out pattern until I realised that some accounts were set as "never expire". Don't trust it now ant wondering if I should force it now but some users will have to change their password twice! Grr!
mavhc Posted February 12, 2020 Posted February 12, 2020 If you set a max password age and untick never expire, it should work and ignore those with a new password
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now