"User must change password at next logon" settings
i administering 2008 r2 domain. when new user accounts created, set temporary password , check "user must change password @ next logon" box on user account in aduc. controlled the default domain policy, our account passwords expire every 30 days. policy apply temporary passwords before account accessed first time?
if you assign password user and check "user must change password @ next logon", pwdlastset attribute assigned 0. condition can last forever. eventually, when user logs on first time, if years later, password assigned still works, they must change password, , system assigns value corresponding current date pwdlastset. if maxpwdage 30 days, password next expire 30 days later (30 days after user first logged on , changed password). make sense?
richard mueller - mvp directory services
Windows Server > Directory Services
Comments
Post a Comment