Networking Forums

Networking Forums > Computer Networking > Windows Networking > forced cross domain password change....

Reply
Thread Tools Display Modes

forced cross domain password change....

 
 
phatso454@yahoo.com
Guest
Posts: n/a

 
      03-03-2006, 01:39 AM
hi all,

we are running 2 Win2003 native mode domains with a 2 way trust. we
have recently forced a number of users to change their password ("User
must change password at next logon").


problems:


1) some users have computers in a different domain than the one they
logon to. when logging in they are prompted to change their password,
but then get "You do not have permission to change your password". i
read that this may be related to the fact the change password command
is actually intiated by the local computer (to the domain controller)
not the actual user credentials. any ideas on how to make this work?


2) we would like to allow remote users to change their password with
the IIS change password function (iisadmpwd). however, this does NOT
work if the parameter "User must change password at next logon" is
invoked. that is a bummer.


i have done some research and Googled around, but haven't found any
documentation that specifically addresses these issues.
any ideas on how i can smooth these issues out? any help would be
greatly appreciated.


best,
putt

 
Reply With Quote
 
 
 
 
Herb Martin
Guest
Posts: n/a

 
      03-03-2006, 06:13 AM
<(E-Mail Removed)> wrote in message
news:(E-Mail Removed) oups.com...
> hi all,
>
> we are running 2 Win2003 native mode domains with a 2 way trust. we
> have recently forced a number of users to change their password ("User
> must change password at next logon").
>
>
> problems:
>
>
> 1) some users have computers in a different domain than the one they
> logon to. when logging in they are prompted to change their password,
> but then get "You do not have permission to change your password". i
> read that this may be related to the fact the change password command
> is actually intiated by the local computer (to the domain controller)
> not the actual user credentials. any ideas on how to make this work?


Having lived in environments where user accounts were
in one domain and computers in another many times (and
for many years) I have NEVER seen this happen.

My first guess would be your users are NOT actually
authenticated properly (likely due to some DNS problem).

Other than that I would like to see your reference for where
you "read this may be...."

What was the source of that info and what was the full
explanation there?

> 2) we would like to allow remote users to change their password with
> the IIS change password function (iisadmpwd). however, this does NOT
> work if the parameter "User must change password at next logon" is
> invoked. that is a bummer.


My comments above were in reference to a user LOGGING
on to a computer (Cntl-Alt-Del) and not to using IIS where
they are merely AUTHENTICATING (not actually logging
onto the computer.)


> i have done some research and Googled around, but haven't found any
> documentation that specifically addresses these issues.
> any ideas on how i can smooth these issues out? any help would be
> greatly appreciated.


My first thoughts would include running DCDiag on every DC,
and NetDiag on affectied clients machines, capturing the output,
and searching for FAIL, WARN, or IGNORE (fix those problems.)



--
Herb Martin, MCSE, MVP
Accelerated MCSE
http://www.LearnQuick.Com
[phone number on web site]

>
> best,
> putt
>



 
Reply With Quote
 
Cary Shultz
Guest
Posts: n/a

 
      03-03-2006, 10:19 AM
Putt,

I am with Herb on this...it should not matter that the user account objects
are in one Domain and the computer account objects are in another...

--
Cary W. Shultz
Roanoke, VA 24012

<(E-Mail Removed)> wrote in message
news:(E-Mail Removed) oups.com...
> hi all,
>
> we are running 2 Win2003 native mode domains with a 2 way trust. we
> have recently forced a number of users to change their password ("User
> must change password at next logon").
>
>
> problems:
>
>
> 1) some users have computers in a different domain than the one they
> logon to. when logging in they are prompted to change their password,
> but then get "You do not have permission to change your password". i
> read that this may be related to the fact the change password command
> is actually intiated by the local computer (to the domain controller)
> not the actual user credentials. any ideas on how to make this work?
>
>
> 2) we would like to allow remote users to change their password with
> the IIS change password function (iisadmpwd). however, this does NOT
> work if the parameter "User must change password at next logon" is
> invoked. that is a bummer.
>
>
> i have done some research and Googled around, but haven't found any
> documentation that specifically addresses these issues.
> any ideas on how i can smooth these issues out? any help would be
> greatly appreciated.
>
>
> best,
> putt
>



 
Reply With Quote
 
Neil Ruston
Guest
Posts: n/a

 
      03-03-2006, 12:46 PM
Have you checked the rights that SELF has to the user objects?

It should have (at least) Read and Change Password.

neil




"(E-Mail Removed)" wrote:

> hi all,
>
> we are running 2 Win2003 native mode domains with a 2 way trust. we
> have recently forced a number of users to change their password ("User
> must change password at next logon").
>
>
> problems:
>
>
> 1) some users have computers in a different domain than the one they
> logon to. when logging in they are prompted to change their password,
> but then get "You do not have permission to change your password". i
> read that this may be related to the fact the change password command
> is actually intiated by the local computer (to the domain controller)
> not the actual user credentials. any ideas on how to make this work?
>
>
> 2) we would like to allow remote users to change their password with
> the IIS change password function (iisadmpwd). however, this does NOT
> work if the parameter "User must change password at next logon" is
> invoked. that is a bummer.
>
>
> i have done some research and Googled around, but haven't found any
> documentation that specifically addresses these issues.
> any ideas on how i can smooth these issues out? any help would be
> greatly appreciated.
>
>
> best,
> putt
>
>

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
domain wide password change Kirrin Jones Windows Networking 1 12-29-2007 07:28 AM
Force Password change in Domain Tim Windows Networking 4 04-21-2006 09:18 PM
cannot change your password because domain not available BigMo45 Windows Networking 2 11-28-2005 03:02 PM
Unable to change password on 2003 domain Andrew Windows Networking 1 09-30-2003 12:30 PM
change domain password in workgroup Ryan Lo Windows Networking 0 09-24-2003 04:50 AM



1 2 3 4 5 6 7 8 9 10 11