Remote Desktop locks user account on Password ChangeChange Active Directory password over VPNWindows password length warningRemote Desktop Connection for Mac cannot log in to Windows Terminal Server if user's password expiredHow can I lock out remote user from their own computer?Workstations hang on “Change Password” after expired PasswordPassword Expiration / DNS IssueForce user to change AD password at logon before Explorer loads?How can a Windows user change the initial password from the command line in a remote domain?2008 R2 RDS, keeps saying user must change password at first logoncan I reset the clock on an expired password in AD?

Fedora boot screen shows both Fedora logo and Lenovo logo. Why and How?

How many codes are possible?

Why is C++ initial allocation so much larger than C's?

Why isn’t the tax system continuous rather than bracketed?

Does ultrasonic bath cleaning damage laboratory volumetric glassware calibration?

A player is constantly pestering me about rules, what do I do as a DM?

C-152 carb heat on before landing in hot weather?

Why aren't (poly-)cotton tents more popular?

Architecture of networked game engine

How can I convince my reader that I will not use a certain trope?

Why would people reject a god's purely beneficial blessing?

Do equal angles necessarily mean a polygon is regular?

Does Marvel have an equivalent of the Green Lantern?

How often can a PC check with passive perception during a combat turn?

What is this opening trap called, and how should I play afterwards? How can I refute the gambit, and play if I accept it?

Should I include salary information on my CV?

Why do some games show lights shine through walls?

Could Sauron have read Tom Bombadil's mind if Tom had held the Palantir?

Swapping rooks in a 4x4 board

Short story with brother-sister conjoined twins as protagonists?

Finding closed forms for various addition laws on elliptic curves, FullSimplify fails even with assumptions?

Can a US President have someone sent to prison?

Going to get married soon, should I do it on Dec 31 or Jan 1?

How come I was asked by a CBP officer why I was in the US?



Remote Desktop locks user account on Password Change


Change Active Directory password over VPNWindows password length warningRemote Desktop Connection for Mac cannot log in to Windows Terminal Server if user's password expiredHow can I lock out remote user from their own computer?Workstations hang on “Change Password” after expired PasswordPassword Expiration / DNS IssueForce user to change AD password at logon before Explorer loads?How can a Windows user change the initial password from the command line in a remote domain?2008 R2 RDS, keeps saying user must change password at first logoncan I reset the clock on an expired password in AD?






.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty margin-bottom:0;








2















We maintain a Terminal Server on our network for our remote office and occasional third party vendors to connect in to. Our windows network active directory has the standard windows password requirements (i.e. 3 out of the 4 character types, expires every 3 months, can't reuse password, etc.)



What I am noticing is that when someone logs into the remote server and is prompted to change their password, it does change the password but then it immediately locks their account. I then need to pop into the AD and unlock them before they can use it again, which is problematic for both offices.



Is there a setting that is causing this? Something I can disable. I do not want to turn off the password rules, or set up all these users with passwords that never expire if I can help it.



TIA










share|improve this question






















  • Not remote desktop, but we had other services instantly lock out on password change, the solution was to set password history to 1 instead of 0, then the DCs knew it was an old password, not incorrect.

    – WhoIsRich
    Nov 26 '13 at 16:19

















2















We maintain a Terminal Server on our network for our remote office and occasional third party vendors to connect in to. Our windows network active directory has the standard windows password requirements (i.e. 3 out of the 4 character types, expires every 3 months, can't reuse password, etc.)



What I am noticing is that when someone logs into the remote server and is prompted to change their password, it does change the password but then it immediately locks their account. I then need to pop into the AD and unlock them before they can use it again, which is problematic for both offices.



Is there a setting that is causing this? Something I can disable. I do not want to turn off the password rules, or set up all these users with passwords that never expire if I can help it.



TIA










share|improve this question






















  • Not remote desktop, but we had other services instantly lock out on password change, the solution was to set password history to 1 instead of 0, then the DCs knew it was an old password, not incorrect.

    – WhoIsRich
    Nov 26 '13 at 16:19













2












2








2








We maintain a Terminal Server on our network for our remote office and occasional third party vendors to connect in to. Our windows network active directory has the standard windows password requirements (i.e. 3 out of the 4 character types, expires every 3 months, can't reuse password, etc.)



What I am noticing is that when someone logs into the remote server and is prompted to change their password, it does change the password but then it immediately locks their account. I then need to pop into the AD and unlock them before they can use it again, which is problematic for both offices.



Is there a setting that is causing this? Something I can disable. I do not want to turn off the password rules, or set up all these users with passwords that never expire if I can help it.



TIA










share|improve this question














We maintain a Terminal Server on our network for our remote office and occasional third party vendors to connect in to. Our windows network active directory has the standard windows password requirements (i.e. 3 out of the 4 character types, expires every 3 months, can't reuse password, etc.)



What I am noticing is that when someone logs into the remote server and is prompted to change their password, it does change the password but then it immediately locks their account. I then need to pop into the AD and unlock them before they can use it again, which is problematic for both offices.



Is there a setting that is causing this? Something I can disable. I do not want to turn off the password rules, or set up all these users with passwords that never expire if I can help it.



TIA







windows-server-2003 active-directory remote-desktop






share|improve this question













share|improve this question











share|improve this question




share|improve this question










asked Aug 2 '13 at 21:13









Peter LangePeter Lange

5910 bronze badges




5910 bronze badges












  • Not remote desktop, but we had other services instantly lock out on password change, the solution was to set password history to 1 instead of 0, then the DCs knew it was an old password, not incorrect.

    – WhoIsRich
    Nov 26 '13 at 16:19

















  • Not remote desktop, but we had other services instantly lock out on password change, the solution was to set password history to 1 instead of 0, then the DCs knew it was an old password, not incorrect.

    – WhoIsRich
    Nov 26 '13 at 16:19
















Not remote desktop, but we had other services instantly lock out on password change, the solution was to set password history to 1 instead of 0, then the DCs knew it was an old password, not incorrect.

– WhoIsRich
Nov 26 '13 at 16:19





Not remote desktop, but we had other services instantly lock out on password change, the solution was to set password history to 1 instead of 0, then the DCs knew it was an old password, not incorrect.

– WhoIsRich
Nov 26 '13 at 16:19










1 Answer
1






active

oldest

votes


















0














I wish I can comment, but since I can't I'll have to put this as an answer.



I'll take a look at the LockOutStatus (http://www.microsoft.com/en-ca/download/details.aspx?id=15201) and see which DC that user is locked out on. It could be that the user resets their password on one DC then they are authenticated against another. Depending on how long your DC replicates with each other, that user might be authenticating against a DC that have not gotten the new password.



I would check the status on the replication by doing :



repadmin /replsummary


on a DC.



Perhaps increasing the frequency of the replication between DC to more frequent (http://technet.microsoft.com/en-us/library/cc730954.aspx) or AD sites and service is not configured properly with the subnet and sites (http://technet.microsoft.com/en-us/library/cc754697.aspx).






share|improve this answer

























    Your Answer








    StackExchange.ready(function()
    var channelOptions =
    tags: "".split(" "),
    id: "2"
    ;
    initTagRenderer("".split(" "), "".split(" "), channelOptions);

    StackExchange.using("externalEditor", function()
    // Have to fire editor after snippets, if snippets enabled
    if (StackExchange.settings.snippets.snippetsEnabled)
    StackExchange.using("snippets", function()
    createEditor();
    );

    else
    createEditor();

    );

    function createEditor()
    StackExchange.prepareEditor(
    heartbeatType: 'answer',
    autoActivateHeartbeat: false,
    convertImagesToLinks: true,
    noModals: true,
    showLowRepImageUploadWarning: true,
    reputationToPostImages: 10,
    bindNavPrevention: true,
    postfix: "",
    imageUploader:
    brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
    contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
    allowUrls: true
    ,
    onDemand: true,
    discardSelector: ".discard-answer"
    ,immediatelyShowMarkdownHelp:true
    );



    );













    draft saved

    draft discarded


















    StackExchange.ready(
    function ()
    StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f528365%2fremote-desktop-locks-user-account-on-password-change%23new-answer', 'question_page');

    );

    Post as a guest















    Required, but never shown

























    1 Answer
    1






    active

    oldest

    votes








    1 Answer
    1






    active

    oldest

    votes









    active

    oldest

    votes






    active

    oldest

    votes









    0














    I wish I can comment, but since I can't I'll have to put this as an answer.



    I'll take a look at the LockOutStatus (http://www.microsoft.com/en-ca/download/details.aspx?id=15201) and see which DC that user is locked out on. It could be that the user resets their password on one DC then they are authenticated against another. Depending on how long your DC replicates with each other, that user might be authenticating against a DC that have not gotten the new password.



    I would check the status on the replication by doing :



    repadmin /replsummary


    on a DC.



    Perhaps increasing the frequency of the replication between DC to more frequent (http://technet.microsoft.com/en-us/library/cc730954.aspx) or AD sites and service is not configured properly with the subnet and sites (http://technet.microsoft.com/en-us/library/cc754697.aspx).






    share|improve this answer



























      0














      I wish I can comment, but since I can't I'll have to put this as an answer.



      I'll take a look at the LockOutStatus (http://www.microsoft.com/en-ca/download/details.aspx?id=15201) and see which DC that user is locked out on. It could be that the user resets their password on one DC then they are authenticated against another. Depending on how long your DC replicates with each other, that user might be authenticating against a DC that have not gotten the new password.



      I would check the status on the replication by doing :



      repadmin /replsummary


      on a DC.



      Perhaps increasing the frequency of the replication between DC to more frequent (http://technet.microsoft.com/en-us/library/cc730954.aspx) or AD sites and service is not configured properly with the subnet and sites (http://technet.microsoft.com/en-us/library/cc754697.aspx).






      share|improve this answer

























        0












        0








        0







        I wish I can comment, but since I can't I'll have to put this as an answer.



        I'll take a look at the LockOutStatus (http://www.microsoft.com/en-ca/download/details.aspx?id=15201) and see which DC that user is locked out on. It could be that the user resets their password on one DC then they are authenticated against another. Depending on how long your DC replicates with each other, that user might be authenticating against a DC that have not gotten the new password.



        I would check the status on the replication by doing :



        repadmin /replsummary


        on a DC.



        Perhaps increasing the frequency of the replication between DC to more frequent (http://technet.microsoft.com/en-us/library/cc730954.aspx) or AD sites and service is not configured properly with the subnet and sites (http://technet.microsoft.com/en-us/library/cc754697.aspx).






        share|improve this answer













        I wish I can comment, but since I can't I'll have to put this as an answer.



        I'll take a look at the LockOutStatus (http://www.microsoft.com/en-ca/download/details.aspx?id=15201) and see which DC that user is locked out on. It could be that the user resets their password on one DC then they are authenticated against another. Depending on how long your DC replicates with each other, that user might be authenticating against a DC that have not gotten the new password.



        I would check the status on the replication by doing :



        repadmin /replsummary


        on a DC.



        Perhaps increasing the frequency of the replication between DC to more frequent (http://technet.microsoft.com/en-us/library/cc730954.aspx) or AD sites and service is not configured properly with the subnet and sites (http://technet.microsoft.com/en-us/library/cc754697.aspx).







        share|improve this answer












        share|improve this answer



        share|improve this answer










        answered Nov 26 '13 at 15:38









        shinjijaishinjijai

        3513 silver badges14 bronze badges




        3513 silver badges14 bronze badges



























            draft saved

            draft discarded
















































            Thanks for contributing an answer to Server Fault!


            • Please be sure to answer the question. Provide details and share your research!

            But avoid


            • Asking for help, clarification, or responding to other answers.

            • Making statements based on opinion; back them up with references or personal experience.

            To learn more, see our tips on writing great answers.




            draft saved


            draft discarded














            StackExchange.ready(
            function ()
            StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f528365%2fremote-desktop-locks-user-account-on-password-change%23new-answer', 'question_page');

            );

            Post as a guest















            Required, but never shown





















































            Required, but never shown














            Required, but never shown












            Required, but never shown







            Required, but never shown

































            Required, but never shown














            Required, but never shown












            Required, but never shown







            Required, but never shown







            Popular posts from this blog

            Club Baloncesto Breogán Índice Historia | Pavillón | Nome | O Breogán na cultura popular | Xogadores | Adestradores | Presidentes | Palmarés | Historial | Líderes | Notas | Véxase tamén | Menú de navegacióncbbreogan.galCadroGuía oficial da ACB 2009-10, páxina 201Guía oficial ACB 1992, páxina 183. Editorial DB.É de 6.500 espectadores sentados axeitándose á última normativa"Estudiantes Junior, entre as mellores canteiras"o orixinalHemeroteca El Mundo Deportivo, 16 setembro de 1970, páxina 12Historia do BreogánAlfredo Pérez, o último canoneiroHistoria C.B. BreogánHemeroteca de El Mundo DeportivoJimmy Wright, norteamericano do Breogán deixará Lugo por ameazas de morteResultados de Breogán en 1986-87Resultados de Breogán en 1990-91Ficha de Velimir Perasović en acb.comResultados de Breogán en 1994-95Breogán arrasa al Barça. "El Mundo Deportivo", 27 de setembro de 1999, páxina 58CB Breogán - FC BarcelonaA FEB invita a participar nunha nova Liga EuropeaCharlie Bell na prensa estatalMáximos anotadores 2005Tempada 2005-06 : Tódolos Xogadores da Xornada""Non quero pensar nunha man negra, mais pregúntome que está a pasar""o orixinalRaúl López, orgulloso dos xogadores, presume da boa saúde económica do BreogánJulio González confirma que cesa como presidente del BreogánHomenaxe a Lisardo GómezA tempada do rexurdimento celesteEntrevista a Lisardo GómezEl COB dinamita el Pazo para forzar el quinto (69-73)Cafés Candelas, patrocinador del CB Breogán"Suso Lázare, novo presidente do Breogán"o orixinalCafés Candelas Breogán firma el mayor triunfo de la historiaEl Breogán realizará 17 homenajes por su cincuenta aniversario"O Breogán honra ao seu fundador e primeiro presidente"o orixinalMiguel Giao recibiu a homenaxe do PazoHomenaxe aos primeiros gladiadores celestesO home que nos amosa como ver o Breo co corazónTita Franco será homenaxeada polos #50anosdeBreoJulio Vila recibirá unha homenaxe in memoriam polos #50anosdeBreo"O Breogán homenaxeará aos seus aboados máis veteráns"Pechada ovación a «Capi» Sanmartín e Ricardo «Corazón de González»Homenaxe por décadas de informaciónPaco García volve ao Pazo con motivo do 50 aniversario"Resultados y clasificaciones""O Cafés Candelas Breogán, campión da Copa Princesa""O Cafés Candelas Breogán, equipo ACB"C.B. Breogán"Proxecto social"o orixinal"Centros asociados"o orixinalFicha en imdb.comMario Camus trata la recuperación del amor en 'La vieja música', su última película"Páxina web oficial""Club Baloncesto Breogán""C. B. Breogán S.A.D."eehttp://www.fegaba.com

            Vilaño, A Laracha Índice Patrimonio | Lugares e parroquias | Véxase tamén | Menú de navegación43°14′52″N 8°36′03″O / 43.24775, -8.60070

            Cegueira Índice Epidemioloxía | Deficiencia visual | Tipos de cegueira | Principais causas de cegueira | Tratamento | Técnicas de adaptación e axudas | Vida dos cegos | Primeiros auxilios | Crenzas respecto das persoas cegas | Crenzas das persoas cegas | O neno deficiente visual | Aspectos psicolóxicos da cegueira | Notas | Véxase tamén | Menú de navegación54.054.154.436928256blindnessDicionario da Real Academia GalegaPortal das Palabras"International Standards: Visual Standards — Aspects and Ranges of Vision Loss with Emphasis on Population Surveys.""Visual impairment and blindness""Presentan un plan para previr a cegueira"o orixinalACCDV Associació Catalana de Cecs i Disminuïts Visuals - PMFTrachoma"Effect of gene therapy on visual function in Leber's congenital amaurosis"1844137110.1056/NEJMoa0802268Cans guía - os mellores amigos dos cegosArquivadoEscola de cans guía para cegos en Mortágua, PortugalArquivado"Tecnología para ciegos y deficientes visuales. Recopilación de recursos gratuitos en la Red""Colorino""‘COL.diesis’, escuchar los sonidos del color""COL.diesis: Transforming Colour into Melody and Implementing the Result in a Colour Sensor Device"o orixinal"Sistema de desarrollo de sinestesia color-sonido para invidentes utilizando un protocolo de audio""Enseñanza táctil - geometría y color. Juegos didácticos para niños ciegos y videntes""Sistema Constanz"L'ocupació laboral dels cecs a l'Estat espanyol està pràcticament equiparada a la de les persones amb visió, entrevista amb Pedro ZuritaONCE (Organización Nacional de Cegos de España)Prevención da cegueiraDescrición de deficiencias visuais (Disc@pnet)Braillín, un boneco atractivo para calquera neno, con ou sen discapacidade, que permite familiarizarse co sistema de escritura e lectura brailleAxudas Técnicas36838ID00897494007150-90057129528256DOID:1432HP:0000618D001766C10.597.751.941.162C97109C0155020