"User must change password at next logon" settings


i administering 2008 r2 domain.  when new user accounts created, set temporary password , check "user must change password @ next logon" box on user account in aduc.  controlled the default domain policy, our account passwords expire every 30 days.  policy apply temporary passwords before account accessed first time? 

if you assign password user and check "user must change password @ next logon", pwdlastset attribute assigned 0. condition can last forever. eventually, when user logs on first time, if years later, password assigned still works, they must change password, , system assigns value corresponding current date pwdlastset. if maxpwdage 30 days, password next expire 30 days later (30 days after user first logged on , changed password). make sense?


richard mueller - mvp directory services



Windows Server  >  Directory Services



Comments

Popular posts from this blog

CRL Revocation always failed

Failed to query the results of bpa xpath

0x300000d errors in Microsoft Remote Desktop client