Skip Navigation Links
 
Skip navigation links
Home
Events
Communication and Collaboration
Desktop Tools
Infrastructure
Server Applications
Site Map
About
 
Skip navigation links
Windows Server
Library
News
Forum
Wiki
Modify settings and columns

Forum

  
View: 
Post
Started: 26/09/2008 12:18
Picture Placeholder: IanS
IanS
Not able to change "Users must change password at next logon" attribute for Multiple Users simultaneously server 2008 ADUC
Hi there every one, just thought i would share the following with you
 
I have been working on an issue where the functionality in

Active directory users and computers in 2008 differs from that of 2003, in this case bulk updating users

 

To reproduce the issue

You want to change "Users must change password at next logon" attribute for Multiple Users simultaneously

1:  got to your 2008 server, look at ADUC select multiple users to make the change to.

2: Right click and go to properties

3: Accounts Tab

4: Select the first and second check box for "Users must change password at next logon" attribute

5: ok it

 

now at this point if you go back to any of the users and check to see if the tick box next to "Users must change password at next logon"  is still checked you will find the answer to this is no.

 

ok whats going on here then, if you go to your 2003 ADUC you will find if you do the same thing then yes the check box is in fact ticked. So why is it not working in 2008,

 

ok back to your 2008 server and do as before

 

1:  got to your 2008 server, look at ADUC select multiple users to make the change to.

2: Right click and go to properties

3: Accounts Tab

4: Select the first and second check box for "Users must change password at next logon" attribute

 

now come the change

 

5: you have to check “User cannot change password” and “Password never expires” by selecting the First Check Box only on the two atributes below

choose ok 

 

now if you go back and look at any of the users you will see that the "Users must change password at next logon" tick box is now ticked ;-)

 

ok why is this your going to ask, and why is it by design.

 

well if you think about it, say you want to bulk update 100 users and out of thoses 100 users 4 of them have

"User cannot change password"  then think what are you trying to do at the moment "Users must change password at next logon" so theres going to be a conflick and issues will arise where the user has not got the right to change there password even though they are being told they must.

checking thoses first two boxes clears the  "User cannot change password" out of thoses 100 users and then aloows the user to change there password at next logon ;-)

 

i hope this has made sense to every one and come in handy,