Re: change client password



Is this new or ongoing behavior?? The first two things I would check is that
the properties in the user's account in ADUC does not show that can not
change password is enabled and that the minimum password age is not set too
high which generally does not need to be more than two days. You can run the
command net accounts on a domain controller to quickly see that setting
which usually is set by Domain Security Policy unless you have configured
additional GPOs linked to the domain container that are higher in the
priority list than the default domain GPO that have minimum password age
configured. Also make sure that the client computers can contact a domain
controller or the password change will fail. The support tool netdiag will
show errors/warnings if a domain controller can not be found or contacted
when run on a domain client computer.

Steve


"jimi hendrix" <jimihendrix@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:D2AA3C1D-9010-4AFE-BA37-BA5481EF57E0@xxxxxxxxxxxxxxxx
my client are not able to change their domain password.
error unable to change password
They exist in a windows 2000 ad domain, as far as i can see there is no
policy preventing the clients from changing their domain logon password
can anyone point me in the right direction, thanks in advance


.



Relevant Pages

  • Re: Domain users unable to change password
    ... are not configured to not allow user to change password in account ... I can't think of a Group Policy setting offhand but if you have a Windows ... 2003 domain controller try running the Resultant Set of Policy mmc snapin in ... connectivity, replication, and secure channel/computer account integrity. ...
    (microsoft.public.windows.group_policy)
  • Re: Security Breach in AD! Help!
    ... > about 5 minutes the user was removed from the built in admin group. ... > changed the default domain policy, the default domain controller policy, ... >> auditing of account logon for success and failure and account management ... >> success and failure in Domain Controller Security Policy. ...
    (microsoft.public.win2000.security)
  • Re: disable users while user is logged into the domain
    ... That article i read more and more before, but it does not state anything about "disabling" an account. ... Assigning an account lockout, which a domain controller performs to ... Changing the password on a domain controller computer account. ... The PDC emulator receives urgent replication of account lockouts. ...
    (microsoft.public.windows.server.active_directory)
  • Re: disable users while user is logged into the domain
    ... Please check the following link for more information concerning urgent replication. ... How the Active Directory Replication Model Works: ... Assigning an account lockout, which a domain controller performs to prohibit a user from logging on after a certain number of failed attempts. ...
    (microsoft.public.windows.server.active_directory)
  • Re: More than one Administrator Account and Reinstalling OS on a D
    ... Some one has created a regular user account and may added that one to ... There is only one built-in administrator peer domain. ... FSMO roles are actually supposed to be transferred automatically during ... When you remove an existing Domain Controller within Active Directory, ...
    (microsoft.public.win2000.active_directory)