Error at remote (RDP) login when "User must change password at next logon" is checked after expired passwords


hello,

we have ad on windows server 2012. several users' password expired (!) , unable connect server using ad-account. connect remotely using windows remote desktop (rdp).

i resetted password using rightclick on ad account , hit "reset password". leave "user must change password @ next logon" checked!

when doing not (leave unchecked), able login set password unable change (maybe due minium password age - group policy. set 1 day, resettet 1 user yesterday still not able change, error occurs saying password not meet gpo, e.g. password restrictions, leglegting point @ moment).

but when having option checked (user must change pw) users wont able connect server. raises authentication error.

i found same problem here there no solution provided:
http://www.experts-exchange.com/os/microsoft_operating_systems/server/windows_server_2008/q_28072013.html

i read ports need opened because ports may opened connect connected users able change pw there must opened additional ports change password before logging in...
unsure , dont want open ports not neccessary.

i can remember created ad accounts , checked "user must change pw..." working @ first time. now, problem, occurs accounts password has been expired, thats difference before think.

i think theres other gpo affected expired passwords dont find such one.

any grateful, thanks!

hi kaspatoo,

this design behavior when nla enabled option to change password @ next logon not work.
nla reason users can’t rdp to server if passwords expired because required to authenticate before remote desktop connection established.

the workground shown below:

-->disable nla
-->change password before logging via mstsc
--> not check “user must change password @ next logon” option when resetting user password
--> instruct users to change passwords before expire to avoid issue.
--> use rdwebaccess password changes.
setup rdwebaccess server to enable password changing option
detailed steps here http://social.technet.microsoft.com/wiki/contents/articles/10755.enabling-the-rd-webaccess-expired-password-reset-option-in-windows-server-2012.aspx

regards,

lany zhang



Windows Server  >  Group Policy



Comments

Popular posts from this blog

some help on Event 540

WMI Repository 4GB limit - Win 2003 Ent Question

Event ID 1302 (error 1307) DFS replication service encountered an error while writing to the debug log file