Re: User get access denied error when prompted to change password adte Reset

From: Mike Robertson (mikerobertson01_at_hotmail.com)
Date: 10/08/04


Date: Fri, 8 Oct 2004 05:48:53 -0700

Thanks Steve, You had it bang on. In a recent audit
finding it was recommended that all anonymous access
privileges should be tightened. Unfortunately "Additional
restrictions for anonymous access" was changed to "no
access without explicit anonymous permission". Once I
changed that and force a policy refresh the problem was
fixed.
Thanks so much for your kind and expeditious assistance.
>-----Original Message-----
>Check their user account properties to make sure they
are not restricted
>from changing passwords. If you enable auditing of
account management in the
>Domain Controller Security Policy, you may find useful
info in the security
>log for failed events for account management. If these
are XP Pro computers
>having this problem, make sure that the domain
controllers do NOT have the
>security option set for "additional restrictions for
anonymous access" set
>to no access without explicit anonymous permissions as
there effective
>setting. You can look under Local Security
Policy/security settings/local
>policies/security options to view the setting and also
check the registry
>setting. See the KB link below for that.
>
>http://support.microsoft.com/?kbid=246261
>
>Depending on your domain makeup make sure that the pdc
fsmo domain
>controller is operational and look in the Event Viewer
of it for any
>problems. It is also possible that the everyone group
does not have proper
>permissions to Active Directory user objects. See the
link below on how to
>check that. --- Steve
>
>http://support.microsoft.com/default.aspx?scid=kb;EN-
US;258788
>
>Try to think if their has been a configuration change
around the time this
>started happening such as importing a security template
or modifying
>security policy on domain controllers or domain
computers as that may be
>related. --- Steve
>
>
>
>"Mike Robertson" <mikerobertson01@hotmail.com> wrote in
message
>news:1ede01c4ac69$3c490b20$a601280a@phx.gbl...
>> When a User request a password reset the user receives
>> a "You do not have access to change your password"
error.
>> I've pruned through all my access, security and Group
>> policies and cannot pinpoint what's overiding the "User
>> must change password at next logon" policy.
>> I am using a temporary workaround but it time
consuming.
>> When the user send a password reset request I change
the
>> password and get the user on the phone. I tell them
what
>> the password is reset to and then have them log in then
>> do a Ctl+Alt+Del and click the change password button
and
>> choose a new password. This as I say though is very
time
>> consuming. Can you help me resolve this problem
>
>
>.
>



Relevant Pages

  • Re: User ASPNET in SQL Server 2000
    ... and turn off anonymous access. ... a logon box will pop up if the user cannot ... >While I love integrated security in SQL Server, ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: WCF and Integrated Windows Authentication
    ... anonymous access in IIS. ... should be used as the security identity when your ASP.NET web app calling ... you can try explicitly specify a client credentials (when calling the WCF ... You can send feedback directly to my manager at: ...
    (microsoft.public.dotnet.framework.aspnet.webservices)
  • Re: 401.1 Error w/ Anonymous Access
    ... > - I've set up a local account on the machine (Win2000 Professional, ... > - In the local machine's Local Security Policy I've allowed SiteUser to ... I am under the impression that if Anonymous Access is ... IIS will treat the request as if it is coming from the user ...
    (microsoft.public.inetserver.iis.security)
  • Re: How to provide Log Off for a Web Application?
    ... > someone to delete all your non-secured data, ... Well, actually, for this particular app, anonymous access is read-only ... security can be shades of grey. ... I approve of browser applications which provide a log out feature. ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: SPS vs. WSS and webpublishing
    ... or outside the firewall with anonymous access, ... site level can be on the inside of the firewall? ... >and another level of security at a sub-site level. ...
    (microsoft.public.sharepoint.windowsservices)