Re: Can't log in after password expires

From: Steven L Umbach (n9rou_at_n0-spam-for-me-comcast.net)
Date: 09/30/04

  • Next message: Kanaiya: "win 2k server Admin password Not able to recover"
    Date: Thu, 30 Sep 2004 02:02:25 GMT
    
    

    What is the exact error message they get and what is the operating system of
    the computer they are logging onto? Make sure that users are allowed to
    change passwords by checking their computer account/account/properties to
    verify that their account is not configured to not allow user to change
    password. Can they change their passwords before they expire after logging
    onto their computer and using ctrl-alt-delete?? Enable auditing of account
    logon and account management events in the Domain Controller Security policy
    and look for related events when a user experiences this to see if any of
    the events in the security log give a clue and also check the system and
    application logs of the domain controllers for any errors that may be
    related. --- Steve

    http://www.microsoft.com/technet/security/guidance/secmod144.mspx

    "Aleshka" <anonymous@discussions.microsoft.com> wrote in message
    news:3fb301c4a683$0ced4760$a501280a@phx.gbl...
    >I have the administrative rights to my user computers on
    > Windows 2000 server. Once the user passwords fully expire
    > they are prompted to change it. Upon changing it, they
    > are still not allowed to log in which case they have to
    > come to the admin computer and have it manualy change
    > from there.
    >
    > Is there a way or a setting that will enable the users to
    > just change the password from their workstation once the
    > password expires?
    >
    > Thanks,
    >
    > Alex


  • Next message: Kanaiya: "win 2k server Admin password Not able to recover"

    Relevant Pages

    • Novell and XP Pro
      ... Having trouble with user names and passwords mixing up ... with XP pro and a Novell Server. ... logging on as a different person on Novell and then ... even worse, when we delete an account in XP, it may change ...
      (microsoft.public.windowsxp.security_admin)
    • Re: Account lockouts
      ... for reusable passwords and the AAA infrastructures that rely upon them? ... In that context, account lockout policy -- duration, threshold, lockout ... > cracking attacks. ...
      (microsoft.public.security)
    • Re: Deleting Admin Account
      ... administrative level account to change the Type of the Admin account ... created to a limited account (or create yourself a third account - non-admin ... The built-in administrator cannot be changed from the administrative level, ... You should password protect (with different passwords would be best) each ...
      (microsoft.public.windowsxp.setup_deployment)
    • Re: Blank Passwords, Complex Requeirements and Problems...
      ... The account would then have: 544 = normal account with "Password Not Required" bit = on ... wellKnownObjects: B:32:6227F0AF1FC2410D8E3BB10615BB5B0F:CN=NTDS ... BLOG --> http://blogs.dirteam.com/blogs/jorge/default.aspx ... As far as i know, the Win2003 AD never had a "free" Default Domain Policy to allow that, the DDP is the Default since the initial build of th AD. Ok, let's say that an Admin disabled temporarily th DDP for a few moments and allowed certain accouns to be created with blank passwords. ...
      (microsoft.public.win2000.active_directory)
    • RE: Threat vector of running a service using a domain account
      ... Cachedumps are for local logon password dumps. ... Lsadumps retrieve the passwords in plaintext (each char. ... Cachedump, which again, doesn't work so well against the latest versions ... Threat vector of running a service using a domain account ...
      (Security-Basics)