Remote Desktop locks user account on Password ChangeChange Active Directory password over VPNWindows password length warningRemote Desktop Connection for Mac cannot log in to Windows Terminal Server if user's password expiredHow can I lock out remote user from their own computer?Workstations hang on “Change Password” after expired PasswordPassword Expiration / DNS IssueForce user to change AD password at logon before Explorer loads?How can a Windows user change the initial password from the command line in a remote domain?2008 R2 RDS, keeps saying user must change password at first logoncan I reset the clock on an expired password in AD?

Fedora boot screen shows both Fedora logo and Lenovo logo. Why and How?

How many codes are possible?

Why is C++ initial allocation so much larger than C's?

Why isn’t the tax system continuous rather than bracketed?

Does ultrasonic bath cleaning damage laboratory volumetric glassware calibration?

A player is constantly pestering me about rules, what do I do as a DM?

C-152 carb heat on before landing in hot weather?

Why aren't (poly-)cotton tents more popular?

Architecture of networked game engine

How can I convince my reader that I will not use a certain trope?

Why would people reject a god's purely beneficial blessing?

Do equal angles necessarily mean a polygon is regular?

Does Marvel have an equivalent of the Green Lantern?

How often can a PC check with passive perception during a combat turn?

What is this opening trap called, and how should I play afterwards? How can I refute the gambit, and play if I accept it?

Should I include salary information on my CV?

Why do some games show lights shine through walls?

Could Sauron have read Tom Bombadil's mind if Tom had held the Palantir?

Swapping rooks in a 4x4 board

Short story with brother-sister conjoined twins as protagonists?

Finding closed forms for various addition laws on elliptic curves, FullSimplify fails even with assumptions?

Can a US President have someone sent to prison?

Going to get married soon, should I do it on Dec 31 or Jan 1?

How come I was asked by a CBP officer why I was in the US?



Remote Desktop locks user account on Password Change


Change Active Directory password over VPNWindows password length warningRemote Desktop Connection for Mac cannot log in to Windows Terminal Server if user's password expiredHow can I lock out remote user from their own computer?Workstations hang on “Change Password” after expired PasswordPassword Expiration / DNS IssueForce user to change AD password at logon before Explorer loads?How can a Windows user change the initial password from the command line in a remote domain?2008 R2 RDS, keeps saying user must change password at first logoncan I reset the clock on an expired password in AD?






.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty margin-bottom:0;








2















We maintain a Terminal Server on our network for our remote office and occasional third party vendors to connect in to. Our windows network active directory has the standard windows password requirements (i.e. 3 out of the 4 character types, expires every 3 months, can't reuse password, etc.)



What I am noticing is that when someone logs into the remote server and is prompted to change their password, it does change the password but then it immediately locks their account. I then need to pop into the AD and unlock them before they can use it again, which is problematic for both offices.



Is there a setting that is causing this? Something I can disable. I do not want to turn off the password rules, or set up all these users with passwords that never expire if I can help it.



TIA










share|improve this question






















  • Not remote desktop, but we had other services instantly lock out on password change, the solution was to set password history to 1 instead of 0, then the DCs knew it was an old password, not incorrect.

    – WhoIsRich
    Nov 26 '13 at 16:19

















2















We maintain a Terminal Server on our network for our remote office and occasional third party vendors to connect in to. Our windows network active directory has the standard windows password requirements (i.e. 3 out of the 4 character types, expires every 3 months, can't reuse password, etc.)



What I am noticing is that when someone logs into the remote server and is prompted to change their password, it does change the password but then it immediately locks their account. I then need to pop into the AD and unlock them before they can use it again, which is problematic for both offices.



Is there a setting that is causing this? Something I can disable. I do not want to turn off the password rules, or set up all these users with passwords that never expire if I can help it.



TIA










share|improve this question






















  • Not remote desktop, but we had other services instantly lock out on password change, the solution was to set password history to 1 instead of 0, then the DCs knew it was an old password, not incorrect.

    – WhoIsRich
    Nov 26 '13 at 16:19













2












2








2








We maintain a Terminal Server on our network for our remote office and occasional third party vendors to connect in to. Our windows network active directory has the standard windows password requirements (i.e. 3 out of the 4 character types, expires every 3 months, can't reuse password, etc.)



What I am noticing is that when someone logs into the remote server and is prompted to change their password, it does change the password but then it immediately locks their account. I then need to pop into the AD and unlock them before they can use it again, which is problematic for both offices.



Is there a setting that is causing this? Something I can disable. I do not want to turn off the password rules, or set up all these users with passwords that never expire if I can help it.



TIA










share|improve this question














We maintain a Terminal Server on our network for our remote office and occasional third party vendors to connect in to. Our windows network active directory has the standard windows password requirements (i.e. 3 out of the 4 character types, expires every 3 months, can't reuse password, etc.)



What I am noticing is that when someone logs into the remote server and is prompted to change their password, it does change the password but then it immediately locks their account. I then need to pop into the AD and unlock them before they can use it again, which is problematic for both offices.



Is there a setting that is causing this? Something I can disable. I do not want to turn off the password rules, or set up all these users with passwords that never expire if I can help it.



TIA







windows-server-2003 active-directory remote-desktop






share|improve this question













share|improve this question











share|improve this question




share|improve this question










asked Aug 2 '13 at 21:13









Peter LangePeter Lange

5910 bronze badges




5910 bronze badges












  • Not remote desktop, but we had other services instantly lock out on password change, the solution was to set password history to 1 instead of 0, then the DCs knew it was an old password, not incorrect.

    – WhoIsRich
    Nov 26 '13 at 16:19

















  • Not remote desktop, but we had other services instantly lock out on password change, the solution was to set password history to 1 instead of 0, then the DCs knew it was an old password, not incorrect.

    – WhoIsRich
    Nov 26 '13 at 16:19
















Not remote desktop, but we had other services instantly lock out on password change, the solution was to set password history to 1 instead of 0, then the DCs knew it was an old password, not incorrect.

– WhoIsRich
Nov 26 '13 at 16:19





Not remote desktop, but we had other services instantly lock out on password change, the solution was to set password history to 1 instead of 0, then the DCs knew it was an old password, not incorrect.

– WhoIsRich
Nov 26 '13 at 16:19










1 Answer
1






active

oldest

votes


















0














I wish I can comment, but since I can't I'll have to put this as an answer.



I'll take a look at the LockOutStatus (http://www.microsoft.com/en-ca/download/details.aspx?id=15201) and see which DC that user is locked out on. It could be that the user resets their password on one DC then they are authenticated against another. Depending on how long your DC replicates with each other, that user might be authenticating against a DC that have not gotten the new password.



I would check the status on the replication by doing :



repadmin /replsummary


on a DC.



Perhaps increasing the frequency of the replication between DC to more frequent (http://technet.microsoft.com/en-us/library/cc730954.aspx) or AD sites and service is not configured properly with the subnet and sites (http://technet.microsoft.com/en-us/library/cc754697.aspx).






share|improve this answer

























    Your Answer








    StackExchange.ready(function()
    var channelOptions =
    tags: "".split(" "),
    id: "2"
    ;
    initTagRenderer("".split(" "), "".split(" "), channelOptions);

    StackExchange.using("externalEditor", function()
    // Have to fire editor after snippets, if snippets enabled
    if (StackExchange.settings.snippets.snippetsEnabled)
    StackExchange.using("snippets", function()
    createEditor();
    );

    else
    createEditor();

    );

    function createEditor()
    StackExchange.prepareEditor(
    heartbeatType: 'answer',
    autoActivateHeartbeat: false,
    convertImagesToLinks: true,
    noModals: true,
    showLowRepImageUploadWarning: true,
    reputationToPostImages: 10,
    bindNavPrevention: true,
    postfix: "",
    imageUploader:
    brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
    contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
    allowUrls: true
    ,
    onDemand: true,
    discardSelector: ".discard-answer"
    ,immediatelyShowMarkdownHelp:true
    );



    );













    draft saved

    draft discarded


















    StackExchange.ready(
    function ()
    StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f528365%2fremote-desktop-locks-user-account-on-password-change%23new-answer', 'question_page');

    );

    Post as a guest















    Required, but never shown

























    1 Answer
    1






    active

    oldest

    votes








    1 Answer
    1






    active

    oldest

    votes









    active

    oldest

    votes






    active

    oldest

    votes









    0














    I wish I can comment, but since I can't I'll have to put this as an answer.



    I'll take a look at the LockOutStatus (http://www.microsoft.com/en-ca/download/details.aspx?id=15201) and see which DC that user is locked out on. It could be that the user resets their password on one DC then they are authenticated against another. Depending on how long your DC replicates with each other, that user might be authenticating against a DC that have not gotten the new password.



    I would check the status on the replication by doing :



    repadmin /replsummary


    on a DC.



    Perhaps increasing the frequency of the replication between DC to more frequent (http://technet.microsoft.com/en-us/library/cc730954.aspx) or AD sites and service is not configured properly with the subnet and sites (http://technet.microsoft.com/en-us/library/cc754697.aspx).






    share|improve this answer



























      0














      I wish I can comment, but since I can't I'll have to put this as an answer.



      I'll take a look at the LockOutStatus (http://www.microsoft.com/en-ca/download/details.aspx?id=15201) and see which DC that user is locked out on. It could be that the user resets their password on one DC then they are authenticated against another. Depending on how long your DC replicates with each other, that user might be authenticating against a DC that have not gotten the new password.



      I would check the status on the replication by doing :



      repadmin /replsummary


      on a DC.



      Perhaps increasing the frequency of the replication between DC to more frequent (http://technet.microsoft.com/en-us/library/cc730954.aspx) or AD sites and service is not configured properly with the subnet and sites (http://technet.microsoft.com/en-us/library/cc754697.aspx).






      share|improve this answer

























        0












        0








        0







        I wish I can comment, but since I can't I'll have to put this as an answer.



        I'll take a look at the LockOutStatus (http://www.microsoft.com/en-ca/download/details.aspx?id=15201) and see which DC that user is locked out on. It could be that the user resets their password on one DC then they are authenticated against another. Depending on how long your DC replicates with each other, that user might be authenticating against a DC that have not gotten the new password.



        I would check the status on the replication by doing :



        repadmin /replsummary


        on a DC.



        Perhaps increasing the frequency of the replication between DC to more frequent (http://technet.microsoft.com/en-us/library/cc730954.aspx) or AD sites and service is not configured properly with the subnet and sites (http://technet.microsoft.com/en-us/library/cc754697.aspx).






        share|improve this answer













        I wish I can comment, but since I can't I'll have to put this as an answer.



        I'll take a look at the LockOutStatus (http://www.microsoft.com/en-ca/download/details.aspx?id=15201) and see which DC that user is locked out on. It could be that the user resets their password on one DC then they are authenticated against another. Depending on how long your DC replicates with each other, that user might be authenticating against a DC that have not gotten the new password.



        I would check the status on the replication by doing :



        repadmin /replsummary


        on a DC.



        Perhaps increasing the frequency of the replication between DC to more frequent (http://technet.microsoft.com/en-us/library/cc730954.aspx) or AD sites and service is not configured properly with the subnet and sites (http://technet.microsoft.com/en-us/library/cc754697.aspx).







        share|improve this answer












        share|improve this answer



        share|improve this answer










        answered Nov 26 '13 at 15:38









        shinjijaishinjijai

        3513 silver badges14 bronze badges




        3513 silver badges14 bronze badges



























            draft saved

            draft discarded
















































            Thanks for contributing an answer to Server Fault!


            • Please be sure to answer the question. Provide details and share your research!

            But avoid


            • Asking for help, clarification, or responding to other answers.

            • Making statements based on opinion; back them up with references or personal experience.

            To learn more, see our tips on writing great answers.




            draft saved


            draft discarded














            StackExchange.ready(
            function ()
            StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f528365%2fremote-desktop-locks-user-account-on-password-change%23new-answer', 'question_page');

            );

            Post as a guest















            Required, but never shown





















































            Required, but never shown














            Required, but never shown












            Required, but never shown







            Required, but never shown

































            Required, but never shown














            Required, but never shown












            Required, but never shown







            Required, but never shown







            Popular posts from this blog

            Wikipedia:Vital articles Мазмуну Biography - Өмүр баян Philosophy and psychology - Философия жана психология Religion - Дин Social sciences - Коомдук илимдер Language and literature - Тил жана адабият Science - Илим Technology - Технология Arts and recreation - Искусство жана эс алуу History and geography - Тарых жана география Навигация менюсу

            Bruxelas-Capital Índice Historia | Composición | Situación lingüística | Clima | Cidades irmandadas | Notas | Véxase tamén | Menú de navegacióneO uso das linguas en Bruxelas e a situación do neerlandés"Rexión de Bruxelas Capital"o orixinalSitio da rexiónPáxina de Bruselas no sitio da Oficina de Promoción Turística de Valonia e BruxelasMapa Interactivo da Rexión de Bruxelas-CapitaleeWorldCat332144929079854441105155190212ID28008674080552-90000 0001 0666 3698n94104302ID540940339365017018237

            What should I write in an apology letter, since I have decided not to join a company after accepting an offer letterShould I keep looking after accepting a job offer?What should I do when I've been verbally told I would get an offer letter, but still haven't gotten one after 4 weeks?Do I accept an offer from a company that I am not likely to join?New job hasn't confirmed starting date and I want to give current employer as much notice as possibleHow should I address my manager in my resignation letter?HR delayed background verification, now jobless as resignedNo email communication after accepting a formal written offer. How should I phrase the call?What should I do if after receiving a verbal offer letter I am informed that my written job offer is put on hold due to some internal issues?Should I inform the current employer that I am about to resign within 1-2 weeks since I have signed the offer letter and waiting for visa?What company will do, if I send their offer letter to another company