Domain users unable to change password with Net User


my environment predominately server 2008 r2, have application admins unable use net user change own passwords elevated command line. have checked permissions , have both reset , change permissions user object.

using "net user [username] * /domain" still access denied, works if give them full control. there permission missing aside change , reset? feel missing silly here.

edit: password policy follows:

enforce password history 24

maximum password age 60

minimum password age 1

minimum password length 14

password must meet complexity requirements enabled

store passwords using reversible encryption disabled

no fgpp


the group must have change password permissions on computer , user objects unauthenticated or "anonymous" users or computers able change passwords when expire without having authenticated first. if anonymous user denied ability change passwords, user unable change password without logging on.

richard mueller - mvp enterprise mobility (identity , access)



Windows Server  >  Directory Services



Comments

Popular posts from this blog

Group Policy Event ID 1058 Error Code 1326 (The user name or password is incorrect)

Suspicious event log Event ID: 4905

DCOM received error "2147746132" from...