Windows cannot complete password change

M

marcian swaby

This is very strange to me, one of my clients are running an environment
with widows 2000 server sp 4, and for some strange reason they are getting

"windows cannot complete the password change for user _____ because the
password does not meet the pasword policy requirements. Check the minimum
password length, password complexity & password history requirements"

I checked all the password policy issues and everything seems to be normal,
this started happening about 3 months ago, I went to microsoft website and
check all the password rules in the active directory restarted the server
even type the command in dos that automatically applies all the changes but
still getting the error message. Hence because I am not able to change the
password, I am unable to add new users into the system. And as you can
figure they are really getting at me for not being able to solve this.

We are unable to change any password from the active directory or even from
computer systems.

Please anybody have any suggestions please help.

Thanks
 
M

Mike Rosado [MSFT]

Hi Marcian,

I'm by no means an expert in this subject matter of Active Directory, but
I'll try to assist you to the best of my ability. See if the following
steps help you resolve this issue:

1. Click on Start > Run and type adsiedit.msc
2. Expand the Domain NC
3. Expand DC=<domainname>
4. Find and Right Click on the User object and click on Properties
5. Check the box to "Show mandatory attributes"
6. Click the box to "Show optional attributes"
7. In the Attributes field, click on the userParameters attribute
8. Click on the Edit button
9. Click the Clear button and then click OK

Other cases found related to this error indicate this issue can also be due
to migration from Novell, but if no migration has occurred in your case then
disregard the following.

If a Novell migration did occur, then try to re-install FPNW on the PDC
Emulator, uncheck "Maintain NetWare Compatible Login" so that it removes it
from everyone, all the user accounts, click OK and that removes the
attributes. Note that the attribute must be removed on each user.

--
Hope this helps,
Mike Rosado
Windows 2000 MCSE + MCDBA
Microsoft Enterprise Platform Support
Windows NT/2000/2003 Cluster Technologies

====================================================
When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from your issue.
====================================================

This posting is provided "AS IS" with no warranties, and confers no rights.
<http://www.microsoft.com/info/cpyright.htm>

-----Original Message-----
 
M

marcian swaby

Hi Marcian,

I'm by no means an expert in this subject matter of Active Directory, but
I'll try to assist you to the best of my ability. See if the following
steps help you resolve this issue:

1. Click on Start > Run and type adsiedit.msc
2. Expand the Domain NC
3. Expand DC=<domainname>
4. Find and Right Click on the User object and click on Properties
5. Check the box to "Show mandatory attributes"
6. Click the box to "Show optional attributes"
7. In the Attributes field, click on the userParameters attribute
8. Click on the Edit button
9. Click the Clear button and then click OK

Other cases found related to this error indicate this issue can also be due
to migration from Novell, but if no migration has occurred in your case then
disregard the following.

If a Novell migration did occur, then try to re-install FPNW on the PDC
Emulator, uncheck "Maintain NetWare Compatible Login" so that it removes it
from everyone, all the user accounts, click OK and that removes the
attributes. Note that the attribute must be removed on each user.


Ok will try today but there wasn't any migration for novell, thanks for the
help
 
G

Guest

I am having the same problem. I tried to run the adsiedit.msc and it would
not run. It could not find the file. I searched the hard drive and that
file is not there. What am I doing wrong?

Thanks,
Marty
 
Joined
Mar 12, 2008
Messages
2
Reaction score
0
hi


I face the same problem , so i cannot add or change any password,,, i am using windows 2000 server i cannot go through i am.msc,,, why?
I go through net accounts and through gpedit.msc and the following setting appear:

Net accounts:



Microsoft Windows 2000 [Version 5.00.2195]

(C) Copyright 1985-2000 Microsoft Corp.



C:Documents and SettingsAdministrator>net accounts

Force user logoff how long after time expires?: Never

Minimum password age (days): 2

Maximum password age (days): 42

Minimum password length: 8

Length of password history maintained: 24

Lockout threshold: 5

Lockout duration (minutes): 30

Lockout observation window (minutes): 30

Computer role: PRIMARY

The command completed successfully.





On gpedit.msc:

Windows setting—Security settings—account policies—password policy:



Local Setting Effective setting

Enforce password history 0 0

Max password age 42 42

Min password age 0 0

Minimum pass length 0 character 0 character

Pass must meet complexity require disable disable

Store pass using reversible encrypt disable disable







Please any help on this subject as it is serious proplem and need solution
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top