Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations bkrike on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Active Directory: users can't log in after password expiration

Status
Not open for further replies.

SilentDeb

MIS
Mar 18, 2003
9
CA
Hi there,

Forgive me if this is a stupid question - I'm afraid I'm not a network admin, but our helpdesk gets bombarded with calls because of this and I've been asked to research a solution.

Our AD passwords expire every 90 days (feel free to hiss in horror - we know it's not good, but it's a 'political' issue at our workplace), but we have a vast number of users that log on (to an employee self-service website) only a handful of times in a month-long period PER YEAR.

Of course, their passwords have expired by the time they try to log in, but here's the problem - they can't log in at all to RESET their passwords. Those of us log in regularly still have the same problem, if we ignore the 'your password will expire in X days' notice (if we actually take vacation, for example!) - if our passwords expire, we can't get in until someone else resets the password for us.

My online research and mowing through Microsoft's
Active Directory Server book - and indeed, noodling about in AD itself - don't reveal this to be a setting we can control (although I only have partial admin privileges within AD, so I could be missing something). Having read other posts in this forum, it appears that this ISN'T the norm - that normally one can log into an account with an expired password, and just have to reset the password immediately.

What can we do? Does this require some sort of third-party add-in, or is there some setting I can tactfully point the network admins at?

Thanks so much!
 
I know of nothing that allows you to login after the password has been expired to allow you to change it. That would defeat the purpose of having thinks like expired passwords for security reasons.

---------------------------------------
- Submit your sites free to our directory.

- Join our Poker League game.
 
Once your password has expired you should be presented with a "Change Password" screen when trying to log on. Here you would change your password and then gain access to the machine.
 
I agree with rye8261...
As you stated, a user is prompted to change password when the password is soon to expire. If a user does not make the change and the password expires they will not be prompted to change password, show over...

For users who use shared PCs and/or kiosks we place a network password change link on our intranet. It actually points to the link for changing domain passwords from our OWA server, so it is secure through SSL.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top