Remote Desktop locks user account on Password ChangeChange Active Directory password over VPNWindows password length warningRemote Desktop Connection for Mac cannot log in to Windows Terminal Server if user's password expiredHow can I lock out remote user from their own computer?Workstations hang on “Change Password” after expired PasswordPassword Expiration / DNS IssueForce user to change AD password at logon before Explorer loads?How can a Windows user change the initial password from the command line in a remote domain?2008 R2 RDS, keeps saying user must change password at first logoncan I reset the clock on an expired password in AD?
Fedora boot screen shows both Fedora logo and Lenovo logo. Why and How?
How many codes are possible?
Why is C++ initial allocation so much larger than C's?
Why isn’t the tax system continuous rather than bracketed?
Does ultrasonic bath cleaning damage laboratory volumetric glassware calibration?
A player is constantly pestering me about rules, what do I do as a DM?
C-152 carb heat on before landing in hot weather?
Why aren't (poly-)cotton tents more popular?
Architecture of networked game engine
How can I convince my reader that I will not use a certain trope?
Why would people reject a god's purely beneficial blessing?
Do equal angles necessarily mean a polygon is regular?
Does Marvel have an equivalent of the Green Lantern?
How often can a PC check with passive perception during a combat turn?
What is this opening trap called, and how should I play afterwards? How can I refute the gambit, and play if I accept it?
Should I include salary information on my CV?
Why do some games show lights shine through walls?
Could Sauron have read Tom Bombadil's mind if Tom had held the Palantir?
Swapping rooks in a 4x4 board
Short story with brother-sister conjoined twins as protagonists?
Finding closed forms for various addition laws on elliptic curves, FullSimplify fails even with assumptions?
Can a US President have someone sent to prison?
Going to get married soon, should I do it on Dec 31 or Jan 1?
How come I was asked by a CBP officer why I was in the US?
Remote Desktop locks user account on Password Change
Change Active Directory password over VPNWindows password length warningRemote Desktop Connection for Mac cannot log in to Windows Terminal Server if user's password expiredHow can I lock out remote user from their own computer?Workstations hang on “Change Password” after expired PasswordPassword Expiration / DNS IssueForce user to change AD password at logon before Explorer loads?How can a Windows user change the initial password from the command line in a remote domain?2008 R2 RDS, keeps saying user must change password at first logoncan I reset the clock on an expired password in AD?
.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty margin-bottom:0;
We maintain a Terminal Server on our network for our remote office and occasional third party vendors to connect in to. Our windows network active directory has the standard windows password requirements (i.e. 3 out of the 4 character types, expires every 3 months, can't reuse password, etc.)
What I am noticing is that when someone logs into the remote server and is prompted to change their password, it does change the password but then it immediately locks their account. I then need to pop into the AD and unlock them before they can use it again, which is problematic for both offices.
Is there a setting that is causing this? Something I can disable. I do not want to turn off the password rules, or set up all these users with passwords that never expire if I can help it.
TIA
windows-server-2003 active-directory remote-desktop
add a comment |
We maintain a Terminal Server on our network for our remote office and occasional third party vendors to connect in to. Our windows network active directory has the standard windows password requirements (i.e. 3 out of the 4 character types, expires every 3 months, can't reuse password, etc.)
What I am noticing is that when someone logs into the remote server and is prompted to change their password, it does change the password but then it immediately locks their account. I then need to pop into the AD and unlock them before they can use it again, which is problematic for both offices.
Is there a setting that is causing this? Something I can disable. I do not want to turn off the password rules, or set up all these users with passwords that never expire if I can help it.
TIA
windows-server-2003 active-directory remote-desktop
Not remote desktop, but we had other services instantly lock out on password change, the solution was to set password history to 1 instead of 0, then the DCs knew it was an old password, not incorrect.
– WhoIsRich
Nov 26 '13 at 16:19
add a comment |
We maintain a Terminal Server on our network for our remote office and occasional third party vendors to connect in to. Our windows network active directory has the standard windows password requirements (i.e. 3 out of the 4 character types, expires every 3 months, can't reuse password, etc.)
What I am noticing is that when someone logs into the remote server and is prompted to change their password, it does change the password but then it immediately locks their account. I then need to pop into the AD and unlock them before they can use it again, which is problematic for both offices.
Is there a setting that is causing this? Something I can disable. I do not want to turn off the password rules, or set up all these users with passwords that never expire if I can help it.
TIA
windows-server-2003 active-directory remote-desktop
We maintain a Terminal Server on our network for our remote office and occasional third party vendors to connect in to. Our windows network active directory has the standard windows password requirements (i.e. 3 out of the 4 character types, expires every 3 months, can't reuse password, etc.)
What I am noticing is that when someone logs into the remote server and is prompted to change their password, it does change the password but then it immediately locks their account. I then need to pop into the AD and unlock them before they can use it again, which is problematic for both offices.
Is there a setting that is causing this? Something I can disable. I do not want to turn off the password rules, or set up all these users with passwords that never expire if I can help it.
TIA
windows-server-2003 active-directory remote-desktop
windows-server-2003 active-directory remote-desktop
asked Aug 2 '13 at 21:13
Peter LangePeter Lange
5910 bronze badges
5910 bronze badges
Not remote desktop, but we had other services instantly lock out on password change, the solution was to set password history to 1 instead of 0, then the DCs knew it was an old password, not incorrect.
– WhoIsRich
Nov 26 '13 at 16:19
add a comment |
Not remote desktop, but we had other services instantly lock out on password change, the solution was to set password history to 1 instead of 0, then the DCs knew it was an old password, not incorrect.
– WhoIsRich
Nov 26 '13 at 16:19
Not remote desktop, but we had other services instantly lock out on password change, the solution was to set password history to 1 instead of 0, then the DCs knew it was an old password, not incorrect.
– WhoIsRich
Nov 26 '13 at 16:19
Not remote desktop, but we had other services instantly lock out on password change, the solution was to set password history to 1 instead of 0, then the DCs knew it was an old password, not incorrect.
– WhoIsRich
Nov 26 '13 at 16:19
add a comment |
1 Answer
1
active
oldest
votes
I wish I can comment, but since I can't I'll have to put this as an answer.
I'll take a look at the LockOutStatus (http://www.microsoft.com/en-ca/download/details.aspx?id=15201) and see which DC that user is locked out on. It could be that the user resets their password on one DC then they are authenticated against another. Depending on how long your DC replicates with each other, that user might be authenticating against a DC that have not gotten the new password.
I would check the status on the replication by doing :
repadmin /replsummary
on a DC.
Perhaps increasing the frequency of the replication between DC to more frequent (http://technet.microsoft.com/en-us/library/cc730954.aspx) or AD sites and service is not configured properly with the subnet and sites (http://technet.microsoft.com/en-us/library/cc754697.aspx).
add a comment |
Your Answer
StackExchange.ready(function()
var channelOptions =
tags: "".split(" "),
id: "2"
;
initTagRenderer("".split(" "), "".split(" "), channelOptions);
StackExchange.using("externalEditor", function()
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled)
StackExchange.using("snippets", function()
createEditor();
);
else
createEditor();
);
function createEditor()
StackExchange.prepareEditor(
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader:
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
,
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
);
);
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f528365%2fremote-desktop-locks-user-account-on-password-change%23new-answer', 'question_page');
);
Post as a guest
Required, but never shown
1 Answer
1
active
oldest
votes
1 Answer
1
active
oldest
votes
active
oldest
votes
active
oldest
votes
I wish I can comment, but since I can't I'll have to put this as an answer.
I'll take a look at the LockOutStatus (http://www.microsoft.com/en-ca/download/details.aspx?id=15201) and see which DC that user is locked out on. It could be that the user resets their password on one DC then they are authenticated against another. Depending on how long your DC replicates with each other, that user might be authenticating against a DC that have not gotten the new password.
I would check the status on the replication by doing :
repadmin /replsummary
on a DC.
Perhaps increasing the frequency of the replication between DC to more frequent (http://technet.microsoft.com/en-us/library/cc730954.aspx) or AD sites and service is not configured properly with the subnet and sites (http://technet.microsoft.com/en-us/library/cc754697.aspx).
add a comment |
I wish I can comment, but since I can't I'll have to put this as an answer.
I'll take a look at the LockOutStatus (http://www.microsoft.com/en-ca/download/details.aspx?id=15201) and see which DC that user is locked out on. It could be that the user resets their password on one DC then they are authenticated against another. Depending on how long your DC replicates with each other, that user might be authenticating against a DC that have not gotten the new password.
I would check the status on the replication by doing :
repadmin /replsummary
on a DC.
Perhaps increasing the frequency of the replication between DC to more frequent (http://technet.microsoft.com/en-us/library/cc730954.aspx) or AD sites and service is not configured properly with the subnet and sites (http://technet.microsoft.com/en-us/library/cc754697.aspx).
add a comment |
I wish I can comment, but since I can't I'll have to put this as an answer.
I'll take a look at the LockOutStatus (http://www.microsoft.com/en-ca/download/details.aspx?id=15201) and see which DC that user is locked out on. It could be that the user resets their password on one DC then they are authenticated against another. Depending on how long your DC replicates with each other, that user might be authenticating against a DC that have not gotten the new password.
I would check the status on the replication by doing :
repadmin /replsummary
on a DC.
Perhaps increasing the frequency of the replication between DC to more frequent (http://technet.microsoft.com/en-us/library/cc730954.aspx) or AD sites and service is not configured properly with the subnet and sites (http://technet.microsoft.com/en-us/library/cc754697.aspx).
I wish I can comment, but since I can't I'll have to put this as an answer.
I'll take a look at the LockOutStatus (http://www.microsoft.com/en-ca/download/details.aspx?id=15201) and see which DC that user is locked out on. It could be that the user resets their password on one DC then they are authenticated against another. Depending on how long your DC replicates with each other, that user might be authenticating against a DC that have not gotten the new password.
I would check the status on the replication by doing :
repadmin /replsummary
on a DC.
Perhaps increasing the frequency of the replication between DC to more frequent (http://technet.microsoft.com/en-us/library/cc730954.aspx) or AD sites and service is not configured properly with the subnet and sites (http://technet.microsoft.com/en-us/library/cc754697.aspx).
answered Nov 26 '13 at 15:38
shinjijaishinjijai
3513 silver badges14 bronze badges
3513 silver badges14 bronze badges
add a comment |
add a comment |
Thanks for contributing an answer to Server Fault!
- Please be sure to answer the question. Provide details and share your research!
But avoid …
- Asking for help, clarification, or responding to other answers.
- Making statements based on opinion; back them up with references or personal experience.
To learn more, see our tips on writing great answers.
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f528365%2fremote-desktop-locks-user-account-on-password-change%23new-answer', 'question_page');
);
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Not remote desktop, but we had other services instantly lock out on password change, the solution was to set password history to 1 instead of 0, then the DCs knew it was an old password, not incorrect.
– WhoIsRich
Nov 26 '13 at 16:19