Marc
2004-09-21 17:26:50 UTC
Setup,
Windows server 2003 as a DC (patched, up to date)
Client, Windows 2000 Pro, SP4 (patched, up to date)
The problem I'm having is that when I create users and set their account to
"User must change password at next logon", the user gets the message that
their password has expired and they need to change it. They are presented
with the dialog to change the password BUT after a minute they get the
message "The system cannot change your password now because the domain
<domain_name >is not available."
If I go to ADUC and uncheck the option: "User must change password at next
logon", the user can log in w/ no problems. This makes for a pain because I
have to add 150 users and I want the users to set their own passwords.
I've searched Microsoft and found articles: #"837327 and #324141, but
nothing applies. I even experimentd by giving the "Everyone group" special
permissions to the Users OU to "Change Password" and "Reset Password". Then
I tried Everyone "Full Control" just to test if it was a permission issue on
the Users OU. Nothing seems to have any effect.
I know AD is setup right because once the user logs in, the policies are
applied, etc.
I've searched Google groups too, only to be pointed to the old articles at
MS that apply to Windows 2000.
Am I missing something here?
I had our security guys check the firewall and nothing is being denied by
the clients, so I think that helps rule out a firewall issue.
Please Help, this is making me crazy.
Marc
Windows server 2003 as a DC (patched, up to date)
Client, Windows 2000 Pro, SP4 (patched, up to date)
The problem I'm having is that when I create users and set their account to
"User must change password at next logon", the user gets the message that
their password has expired and they need to change it. They are presented
with the dialog to change the password BUT after a minute they get the
message "The system cannot change your password now because the domain
<domain_name >is not available."
If I go to ADUC and uncheck the option: "User must change password at next
logon", the user can log in w/ no problems. This makes for a pain because I
have to add 150 users and I want the users to set their own passwords.
I've searched Microsoft and found articles: #"837327 and #324141, but
nothing applies. I even experimentd by giving the "Everyone group" special
permissions to the Users OU to "Change Password" and "Reset Password". Then
I tried Everyone "Full Control" just to test if it was a permission issue on
the Users OU. Nothing seems to have any effect.
I know AD is setup right because once the user logs in, the policies are
applied, etc.
I've searched Google groups too, only to be pointed to the old articles at
MS that apply to Windows 2000.
Am I missing something here?
I had our security guys check the firewall and nothing is being denied by
the clients, so I think that helps rule out a firewall issue.
Please Help, this is making me crazy.
Marc