Remote Desktop locks user account on Password ChangeChange Active Directory password over VPNWindows password length warningRemote Desktop Connection for Mac cannot log in to Windows Terminal Server if user's password expiredHow can I lock out remote user from their own computer?Workstations hang on “Change Password” after expired PasswordPassword Expiration / DNS IssueForce user to change AD password at logon before Explorer loads?How can a Windows user change the initial password from the command line in a remote domain?2008 R2 RDS, keeps saying user must change password at first logoncan I reset the clock on an expired password in AD?

Fedora boot screen shows both Fedora logo and Lenovo logo. Why and How?

How many codes are possible?

Why is C++ initial allocation so much larger than C's?

Why isn’t the tax system continuous rather than bracketed?

Does ultrasonic bath cleaning damage laboratory volumetric glassware calibration?

A player is constantly pestering me about rules, what do I do as a DM?

C-152 carb heat on before landing in hot weather?

Why aren't (poly-)cotton tents more popular?

Architecture of networked game engine

How can I convince my reader that I will not use a certain trope?

Why would people reject a god's purely beneficial blessing?

Do equal angles necessarily mean a polygon is regular?

Does Marvel have an equivalent of the Green Lantern?

How often can a PC check with passive perception during a combat turn?

What is this opening trap called, and how should I play afterwards? How can I refute the gambit, and play if I accept it?

Should I include salary information on my CV?

Why do some games show lights shine through walls?

Could Sauron have read Tom Bombadil's mind if Tom had held the Palantir?

Swapping rooks in a 4x4 board

Short story with brother-sister conjoined twins as protagonists?

Finding closed forms for various addition laws on elliptic curves, FullSimplify fails even with assumptions?

Can a US President have someone sent to prison?

Going to get married soon, should I do it on Dec 31 or Jan 1?

How come I was asked by a CBP officer why I was in the US?



Remote Desktop locks user account on Password Change


Change Active Directory password over VPNWindows password length warningRemote Desktop Connection for Mac cannot log in to Windows Terminal Server if user's password expiredHow can I lock out remote user from their own computer?Workstations hang on “Change Password” after expired PasswordPassword Expiration / DNS IssueForce user to change AD password at logon before Explorer loads?How can a Windows user change the initial password from the command line in a remote domain?2008 R2 RDS, keeps saying user must change password at first logoncan I reset the clock on an expired password in AD?






.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty margin-bottom:0;








2















We maintain a Terminal Server on our network for our remote office and occasional third party vendors to connect in to. Our windows network active directory has the standard windows password requirements (i.e. 3 out of the 4 character types, expires every 3 months, can't reuse password, etc.)



What I am noticing is that when someone logs into the remote server and is prompted to change their password, it does change the password but then it immediately locks their account. I then need to pop into the AD and unlock them before they can use it again, which is problematic for both offices.



Is there a setting that is causing this? Something I can disable. I do not want to turn off the password rules, or set up all these users with passwords that never expire if I can help it.



TIA










share|improve this question






















  • Not remote desktop, but we had other services instantly lock out on password change, the solution was to set password history to 1 instead of 0, then the DCs knew it was an old password, not incorrect.

    – WhoIsRich
    Nov 26 '13 at 16:19

















2















We maintain a Terminal Server on our network for our remote office and occasional third party vendors to connect in to. Our windows network active directory has the standard windows password requirements (i.e. 3 out of the 4 character types, expires every 3 months, can't reuse password, etc.)



What I am noticing is that when someone logs into the remote server and is prompted to change their password, it does change the password but then it immediately locks their account. I then need to pop into the AD and unlock them before they can use it again, which is problematic for both offices.



Is there a setting that is causing this? Something I can disable. I do not want to turn off the password rules, or set up all these users with passwords that never expire if I can help it.



TIA










share|improve this question






















  • Not remote desktop, but we had other services instantly lock out on password change, the solution was to set password history to 1 instead of 0, then the DCs knew it was an old password, not incorrect.

    – WhoIsRich
    Nov 26 '13 at 16:19













2












2








2








We maintain a Terminal Server on our network for our remote office and occasional third party vendors to connect in to. Our windows network active directory has the standard windows password requirements (i.e. 3 out of the 4 character types, expires every 3 months, can't reuse password, etc.)



What I am noticing is that when someone logs into the remote server and is prompted to change their password, it does change the password but then it immediately locks their account. I then need to pop into the AD and unlock them before they can use it again, which is problematic for both offices.



Is there a setting that is causing this? Something I can disable. I do not want to turn off the password rules, or set up all these users with passwords that never expire if I can help it.



TIA










share|improve this question














We maintain a Terminal Server on our network for our remote office and occasional third party vendors to connect in to. Our windows network active directory has the standard windows password requirements (i.e. 3 out of the 4 character types, expires every 3 months, can't reuse password, etc.)



What I am noticing is that when someone logs into the remote server and is prompted to change their password, it does change the password but then it immediately locks their account. I then need to pop into the AD and unlock them before they can use it again, which is problematic for both offices.



Is there a setting that is causing this? Something I can disable. I do not want to turn off the password rules, or set up all these users with passwords that never expire if I can help it.



TIA







windows-server-2003 active-directory remote-desktop






share|improve this question













share|improve this question











share|improve this question




share|improve this question










asked Aug 2 '13 at 21:13









Peter LangePeter Lange

5910 bronze badges




5910 bronze badges












  • Not remote desktop, but we had other services instantly lock out on password change, the solution was to set password history to 1 instead of 0, then the DCs knew it was an old password, not incorrect.

    – WhoIsRich
    Nov 26 '13 at 16:19

















  • Not remote desktop, but we had other services instantly lock out on password change, the solution was to set password history to 1 instead of 0, then the DCs knew it was an old password, not incorrect.

    – WhoIsRich
    Nov 26 '13 at 16:19
















Not remote desktop, but we had other services instantly lock out on password change, the solution was to set password history to 1 instead of 0, then the DCs knew it was an old password, not incorrect.

– WhoIsRich
Nov 26 '13 at 16:19





Not remote desktop, but we had other services instantly lock out on password change, the solution was to set password history to 1 instead of 0, then the DCs knew it was an old password, not incorrect.

– WhoIsRich
Nov 26 '13 at 16:19










1 Answer
1






active

oldest

votes


















0














I wish I can comment, but since I can't I'll have to put this as an answer.



I'll take a look at the LockOutStatus (http://www.microsoft.com/en-ca/download/details.aspx?id=15201) and see which DC that user is locked out on. It could be that the user resets their password on one DC then they are authenticated against another. Depending on how long your DC replicates with each other, that user might be authenticating against a DC that have not gotten the new password.



I would check the status on the replication by doing :



repadmin /replsummary


on a DC.



Perhaps increasing the frequency of the replication between DC to more frequent (http://technet.microsoft.com/en-us/library/cc730954.aspx) or AD sites and service is not configured properly with the subnet and sites (http://technet.microsoft.com/en-us/library/cc754697.aspx).






share|improve this answer

























    Your Answer








    StackExchange.ready(function()
    var channelOptions =
    tags: "".split(" "),
    id: "2"
    ;
    initTagRenderer("".split(" "), "".split(" "), channelOptions);

    StackExchange.using("externalEditor", function()
    // Have to fire editor after snippets, if snippets enabled
    if (StackExchange.settings.snippets.snippetsEnabled)
    StackExchange.using("snippets", function()
    createEditor();
    );

    else
    createEditor();

    );

    function createEditor()
    StackExchange.prepareEditor(
    heartbeatType: 'answer',
    autoActivateHeartbeat: false,
    convertImagesToLinks: true,
    noModals: true,
    showLowRepImageUploadWarning: true,
    reputationToPostImages: 10,
    bindNavPrevention: true,
    postfix: "",
    imageUploader:
    brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
    contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
    allowUrls: true
    ,
    onDemand: true,
    discardSelector: ".discard-answer"
    ,immediatelyShowMarkdownHelp:true
    );



    );













    draft saved

    draft discarded


















    StackExchange.ready(
    function ()
    StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f528365%2fremote-desktop-locks-user-account-on-password-change%23new-answer', 'question_page');

    );

    Post as a guest















    Required, but never shown

























    1 Answer
    1






    active

    oldest

    votes








    1 Answer
    1






    active

    oldest

    votes









    active

    oldest

    votes






    active

    oldest

    votes









    0














    I wish I can comment, but since I can't I'll have to put this as an answer.



    I'll take a look at the LockOutStatus (http://www.microsoft.com/en-ca/download/details.aspx?id=15201) and see which DC that user is locked out on. It could be that the user resets their password on one DC then they are authenticated against another. Depending on how long your DC replicates with each other, that user might be authenticating against a DC that have not gotten the new password.



    I would check the status on the replication by doing :



    repadmin /replsummary


    on a DC.



    Perhaps increasing the frequency of the replication between DC to more frequent (http://technet.microsoft.com/en-us/library/cc730954.aspx) or AD sites and service is not configured properly with the subnet and sites (http://technet.microsoft.com/en-us/library/cc754697.aspx).






    share|improve this answer



























      0














      I wish I can comment, but since I can't I'll have to put this as an answer.



      I'll take a look at the LockOutStatus (http://www.microsoft.com/en-ca/download/details.aspx?id=15201) and see which DC that user is locked out on. It could be that the user resets their password on one DC then they are authenticated against another. Depending on how long your DC replicates with each other, that user might be authenticating against a DC that have not gotten the new password.



      I would check the status on the replication by doing :



      repadmin /replsummary


      on a DC.



      Perhaps increasing the frequency of the replication between DC to more frequent (http://technet.microsoft.com/en-us/library/cc730954.aspx) or AD sites and service is not configured properly with the subnet and sites (http://technet.microsoft.com/en-us/library/cc754697.aspx).






      share|improve this answer

























        0












        0








        0







        I wish I can comment, but since I can't I'll have to put this as an answer.



        I'll take a look at the LockOutStatus (http://www.microsoft.com/en-ca/download/details.aspx?id=15201) and see which DC that user is locked out on. It could be that the user resets their password on one DC then they are authenticated against another. Depending on how long your DC replicates with each other, that user might be authenticating against a DC that have not gotten the new password.



        I would check the status on the replication by doing :



        repadmin /replsummary


        on a DC.



        Perhaps increasing the frequency of the replication between DC to more frequent (http://technet.microsoft.com/en-us/library/cc730954.aspx) or AD sites and service is not configured properly with the subnet and sites (http://technet.microsoft.com/en-us/library/cc754697.aspx).






        share|improve this answer













        I wish I can comment, but since I can't I'll have to put this as an answer.



        I'll take a look at the LockOutStatus (http://www.microsoft.com/en-ca/download/details.aspx?id=15201) and see which DC that user is locked out on. It could be that the user resets their password on one DC then they are authenticated against another. Depending on how long your DC replicates with each other, that user might be authenticating against a DC that have not gotten the new password.



        I would check the status on the replication by doing :



        repadmin /replsummary


        on a DC.



        Perhaps increasing the frequency of the replication between DC to more frequent (http://technet.microsoft.com/en-us/library/cc730954.aspx) or AD sites and service is not configured properly with the subnet and sites (http://technet.microsoft.com/en-us/library/cc754697.aspx).







        share|improve this answer












        share|improve this answer



        share|improve this answer










        answered Nov 26 '13 at 15:38









        shinjijaishinjijai

        3513 silver badges14 bronze badges




        3513 silver badges14 bronze badges



























            draft saved

            draft discarded
















































            Thanks for contributing an answer to Server Fault!


            • Please be sure to answer the question. Provide details and share your research!

            But avoid


            • Asking for help, clarification, or responding to other answers.

            • Making statements based on opinion; back them up with references or personal experience.

            To learn more, see our tips on writing great answers.




            draft saved


            draft discarded














            StackExchange.ready(
            function ()
            StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f528365%2fremote-desktop-locks-user-account-on-password-change%23new-answer', 'question_page');

            );

            Post as a guest















            Required, but never shown





















































            Required, but never shown














            Required, but never shown












            Required, but never shown







            Required, but never shown

































            Required, but never shown














            Required, but never shown












            Required, but never shown







            Required, but never shown







            Popular posts from this blog

            How to write a 12-bar blues melodyI-IV-V blues progressionHow to play the bridges in a standard blues progressionHow does Gdim7 fit in C# minor?question on a certain chord progressionMusicology of Melody12 bar blues, spread rhythm: alternative to 6th chord to avoid finger stretchChord progressions/ Root key/ MelodiesHow to put chords (POP-EDM) under a given lead vocal melody (starting from a good knowledge in music theory)Are there “rules” for improvising with the minor pentatonic scale over 12-bar shuffle?Confusion about blues scale and chords

            What if the end-user didn't have the required library?What is setup.py?What is a clean, pythonic way to have multiple constructors in Python?What does Ruby have that Python doesn't, and vice versa?What is the reason for having '//' in Python?How do I create a namespace package in Python?How to package shared objects that python modules depend on?setuptools vs. distutils: why is distutils still a thing?Navigation in Windows 10 vs code not going to virtualenv library when the same library is installed at user levelPython create package for local usePackaging a project that uses multiple python versionsWhy is permission denied on pip install except for when “--user” is included at end of command?

            Why did Thanos need his ship to help him in the battle scene?Which actor plays Thanos in the Avengers mid-credits scene?Are there economic implications portrayed in comics where the buildings and cities are ruined almost daily?Old X-Men comic where team travels to alien world with a ring-like sun that needs recharging?Why does Ego need help sleeping?Is there an objective answer to who “the strongest Avenger” is?How did Banner get unstuck?Why did Thanos get hit?How did Thanos (or anyone) know the Infinity Stones would give him this power?Did Thanos leave Eitri alive for his after-sales service?In Avengers 1, why does Thanos need Loki?