Re: Can't get password right in ADAM

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



Hi

it's because ADAM on W2K3 is subject to the effective (windows)
password policy on the server whereas ADAM on WinXP is not subject
to password policy in that way. So if you create an account
on W2K3 then the account is set to disabled if no valid password
is set when the security principal is created.

Lee Flight

"Steven" <Steven@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:22335437-D514-47B3-8539-BCD0783D0044@xxxxxxxxxxxxxxxx
Haha ... here you go. Thanks a lot!
If I remember correctly, XP doesn't have this attribute default to
disabled.
Is it inherited from some where in win 2003?

Thanks again.
Steven

"Lee Flight" wrote:

Hi

check that msDS-UserAccountDisabled is not TRUE on the account.
If that does help please post error you get from ldp.exe

Lee Flight

"Steven" <Steven@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:6E3EE838-C551-45E3-AB8B-E40E6346246F@xxxxxxxxxxxxxxxx
Windows 2003 with ADAM SP1. Everything looks good except setting user
password.

I have tried both ADSI editor and ldp. No error message at all when
setting
the user's password. But can't bind with that password! Time for last
password change looks fine. And YES I got the right prompt if the
password
doesn't meet the min complexity requirements. What can be wrong? Any
log/place to look?

Thanks in advance!





.



Relevant Pages

  • Re: Auditing in ADAM 2003
    ... so you have disabled the password policy using ADAMDisablePasswordPolicies ... Do you have "Audit account logon events" enabled for Success/Failure in your ... ADAM instance security policy, that should give a clue as to activity on the ... "Lee Flight" wrote: ...
    (microsoft.public.windows.server.active_directory)
  • Re: ADAM pwd policies
    ... ADAM on a W2K3 server in a domain will follow the resultant ... password policy on the server. ... you might tune at say, the level of the OU containing the server account. ...
    (microsoft.public.windows.server.active_directory)
  • Re: badPwdCount not Incremented with Membership Provider using ADAM
    ... it is also not true that you are stuck with your domain password policy in ADAM. ... Ideally, ADAM would support password policy completely internal to ADAM, but it currently does not and is wrapped up in the local OS policy enforcement. ... how do I implement them using the membership provider? ...
    (microsoft.public.windows.server.active_directory)
  • Re: using dsadd remotely
    ... The problem with W2K3 is the password policy... ... Change password policy, or change your password to make it meet the ... complexity requirments of W2K3... ...
    (microsoft.public.windows.server.active_directory)
  • Re: ADAM - Remove OS Password Policy Restriction
    ... You can disable enforcement of password policy in ADAM: ... setting ADAMDisablePasswordPolicies, ...
    (microsoft.public.windows.server.active_directory)