User must change password next logon

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Hello

I am noticing something very strange with how AD enforces the attribute "user must change password at next logon" We are running in a Windows 2003 native mode domain with a mix of 2008 and 2003 DC. The Domain naming master is a Windows 2008 box, and it is located in a different site than the user community, but we have a very high speed connection connecting the two sites, so latency is not an issue. I set the attribute user must change password at next logon on 500 user accounts, all client machines are running XP sp3. What we are seeing is the first time a user tries to log on to the domain, they dont get prompted to change the password, if they log off and then try and log back on then they get the prompt. I set the attribute user must change password 2 hours before the first user tried to log in so its not a replication issue. I dont understand why the DC isnt forcing the user to change there password at the first logon attempt from the user?

Many thanks

.



Relevant Pages

  • Re: User must change password at next logon...
    ... I believe it's an 'optimisation' feature of Windows XP. ... "Clementius" wrote in message ... They had to log off and log back in to get the prompt. ... >> am trying to figure out why they were not prompted to change password the ...
    (microsoft.public.windows.server.active_directory)
  • Re: User must change password next logon
    ... Determines whether Windows XP waits for the network during computer ... network to be fully initialized at startup and logon. ... set the attribute user must change password at next logon on 500 user ...
    (microsoft.public.windows.server.active_directory)
  • User must change password at next logon
    ... I have problem with changing passwords at next logon. ... desktop upgrade from Win 2000 to Windows XP and once tech finishes work with ... new desktop I check "User must change password at next logon". ... I run Windows Server 2003 Enterprise as DCs ...
    (microsoft.public.windows.server.active_directory)
  • Re: User must change password next logon
    ... Windows XP does not wait for the network to be fully initialized at startup and logon. ... I am noticing something very strange with how AD enforces the attribute "user must change password at next logon" We are running in a Windows 2003 native mode domain with a mix of 2008 and 2003 DC. ...
    (microsoft.public.windows.server.active_directory)
  • Please assist, password problem
    ... change password before expiration", we came to know ... to 0 days inorder to get the prompt on the same day. ... getting 5 days expiry notice. ... Windows advanced server 2000 so that we can set to windows ...
    (microsoft.public.win2000.security)