RE: Passwords not changing in AD mode

From: ajwayman (ajwayman_at_discussions.microsoft.com)
Date: 12/14/04


Date: Tue, 14 Dec 2004 10:17:02 -0800

THANK YOU! The issue was the group policy setting being undefined. I
changed it; it works, and I am eternally grateful.

"Jim Buyens" wrote:

> Are you sure the password for the WSSDOMAIN\wssaccount hasn't expired? (I
> usually give these sorts of accounts non-expiring passwords and restrict them
> to known computer names.)
>
> The domain controllers and the WSS server are separate machines, right?
>
> On the domain controller is the group policy for Minimum Password Age 0
> days? (This is a requirement).
>
> Jim Buyens
> Microsoft FrontPage MVP
> http://www.interlacken.com
> Author of:
> *----------------------------------------------------
> |\---------------------------------------------------
> || Microsoft Windows SharePoint Services Inside Out
> || Microsoft Office FrontPage 2003 Inside Out
> ||---------------------------------------------------
> || Web Database Development Step by Step .NET Edition
> || Microsoft FrontPage Version 2002 Inside Out
> || Faster Smarter Beginning Programming
> || (All from Microsoft Press)
> |/---------------------------------------------------
> *----------------------------------------------------
>
> "ajwayman" wrote:
>
> > I've been working on this for several months now, and there's too much on my
> > server to wipe it & start over
> >
> > Since I've gotten no help here when I posted before, the only thing I can do
> > is post again, and hope for the best. Even a reply that says, "we're all
> > stumped, and you're SOL" would be better than nothing at this point.
> >
> > I'm running WSS in AD account creation mode. A new issue has come up;
> > changing the password through the website used to work. When a user tries
> > the Change Password feature, they get an error page that says, "Error
> > changing password for user account." The following event shows in the
> > Security log on the domain controller when this happens:
> >
> > Event Type: Failure Audit
> > Event Source: Security
> > Event Category: Account Management
> > Event ID: 627
> > Date: 7/20/2004
> > Time: 3:47:36 PM
> > User: WSSDOMAIN\wssaccount
> > Computer: WSSDC
> > Description:
> > Change Password Attempt:
> > Target Account Name: username
> > Target Domain: WSSDOMAIN
> > Target Account ID: WSSDOMAIN\username
> > Caller User Name: wssacount
> > Caller Domain: WSSDOMAIN
> > Caller Logon ID: (0x0,0x86976)
> > Privileges: -
> >
> > The "wssaccount" has access delegated to the OU for account management. In
> > addition, if I log into the website as the domain admin and change the user's
> > password using the "change password" function, it resets just fine.
> >
> > Actually, a user can change their own password if they are an admin in the
> > subweb they are logged into. However, if they are not an admin, the password
> > change fails.
> >
> > Basically, any time the user is prompted to enter their original password,
> > then the new password, the change doesn't take. However, if they only have
> > to enter the new password (twice), it changes just fine.
> >
> >
> >



Relevant Pages

  • Re: After enabling GPO, client pc needs synchronization
    ... correct DNS configuration. ... Server 2003 domain controllers dynamically register information about ... As far as Group Policy troubleshooting you can use rsop.msc on the client ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Group Policy Delegation of Control
    ... I mean is there in general any impact on domain controllers if group policy ... nothing to do with servers, except some servers related to desktop ... to link GPOs on OUs that contain machines managed by Desktop Team ...
    (microsoft.public.windows.group_policy)
  • Re: Group Policy Delegation of Control
    ... infrastructure, servers, licenses. ... Regarding growth in GPOs: why not to Monitor the growth of GPOs ... downloading the GPO contents and Domain Controllers ... What about utilizing Group Policy for Software Installations, ...
    (microsoft.public.windows.group_policy)
  • Re: Group Policy Editor
    ... don't want to let guests run in an admin account. ... If you mean *some* programs - group policy isn't where you do stuff ... Oh - and don't forget to complain to the product developers about ...
    (microsoft.public.windowsxp.security_admin)
  • Possible Bad Question
    ... Group Policy MMC snap-in on JennyW2KP and configure the account lockout ... lockout Jennifer's Domain Account after two bad logon attempts. ... 2000 Network because the Local Group Policy and Default Domain Controllers ...
    (microsoft.public.cert.exam.mcsa)