New users with Global Password Policy requiring password "reset on first user login" are still prompted to reset password after entering incorrect password

The setup:
We have the option "Password must: be reset on first user login" enabled in the Global Password Policy on our 10.9 / Mavericks server. We import new user accounts into Open Directory via a delimited text file and include a default password for each user.
What I've observed and tested:
When a user attempts to log into a computer that's bound to our Open Directory for the first time, they can enter anything in the password field and still receive the prompt to reset their password. They are never notified that they entered their default password incorrectly. The password reset will then fail (as it should), but they still aren't notified that this is the reason for the password reset failure. To put it another way: Seeing the prompt to reset your password would reasonably imply that you entered the default password correctly, but that's not the case at all.
The question:
Is this expected behavior? If it is, it doesn't seem logical. If this was the case in OS X Server 10.3 through 10.7 I never noticed it. Can anyone corroborate this with their own setup? Thanks in advance.
-- Steve

Some follow up questions:
- How did you migrate (dsmig ldif or binary import)
- Did the accounts in .x have any custom password policies set?
For a "new" and a migrated entry, can you check if a passwordpolicysubentry is configured?
(search as directory manager and fetch the attribute)

Similar Messages

  • UserPrincipal.ChangePassword thinks the password does not meet the password policy requirements.

    I am working with C# 3.5.  My goal is to have a simple program to allow a user change their Active Directory user password via a web page.  I have a console application to initially test the commands to active directory and I am running into a problem.
    my domains password policy is as follows.
    Enforce password history 24 passwords remembered
    Minimum password length 7 characters
    Password must meet complexity requirements Enabled
    Store passwords using reversible encryption Disabled
    The error I am getting is "The password does not meet the password policy requirements. Check the minimum password length, password complexity and password history requirements. (Exception from HRESULT: 0x800708C5)"
    I believe the new password I am using does meet the policy requirements and I can't seem to get this program to work.  All I want to build is a simple program to allow a user to change their Active Directory user password.
    My test code is below.
    using System;
    using System.Collections.Generic;
    using System.Linq;
    using System.Text;
    using System.DirectoryServices.AccountManagement;
    using System.DirectoryServices;
    namespace ActiveDirectoryHacking
    class Program
    static void Main(string[] args)
    PrincipalContext adPrincipalContext = new PrincipalContext(ContextType.Domain, "192.168.1.26", "OU=Staff,DC=SFdev,DC=org", "John.Doe", "Initial Complex P234dfword");
    Console.WriteLine("Validate user {0}", adPrincipalContext.ValidateCredentials("John.Doe", "Initial Complex P234dfword"));
    UserPrincipal user = UserPrincipal.FindByIdentity(adPrincipalContext, "John.Doe");
    Console.WriteLine(user.DistinguishedName);
    user.ChangePassword("Initial Complex P234dfword", "e$213434sDKS really? www.microsoft.com");
    //user.SetPassword("Initial Complex P234dfword");
    user.Save();
    Console.WriteLine("Press a key to exit.");
    Console.ReadKey();
    The .SetPassword works if I use a user with Domain Admin access but it appears the John.Doe is unable to change their own password with the .ChangePassword method.
    The output until the exception is the following
    Validate user True
    CN=John Doe,OU=Staff,DC=SFdev,DC=org
    I have no clue why any password I select for the new password does not work.

    I looked into the password policy and this is what I have learned.  There is a major difference between undefined and defined in policies plus making sure the defined policies are set with values that will provide the desired results.
    Since this is a development domain and is used for testing I have tweaked the password policy to allow me to develop and test against the domain with a little bit more freedom than a production domain.
    I have changed the policy to the following settings. 
    Enforce password history 0 passwords remembered
    Maximum password age 0 days
    Minimum password age 0 days
    Minimum password length 7 characters
    Password must meet complexity requirements Disabled
    Store passwords using reversible encryption Disabled
    Now, I am able to run my program against the domain testing the password change utility.  My error was leaving some of the policy settings as not defined and not understanding what that really means for each setting.  For development of a password change utility I need the flexibility to test and the relaxed policy changes allows me to run the program many times without having to work with test data that works around a more restricted policy.

  • HT201320 PLEASE HELP - I changed my email password on my computer...the email is also on my iPad...I can log on the computer with the 'new' password, however, the iPad is not allowing me to log in.  I continue to get the incorrect password message.  Pleas

    PLEASE HELP - I recently changed my email password on my computer...the email is also on my iPad. I can log on the computer with the 'new' password, however, the iPad is not allowing me to log in.  I continue to get the 'incorrect password' message.  Please advise.

    I'm sorry you're having issues with your e-mail account on your phone Rusty1112. Let's figure out what's going on. First, please try deleting account/information again and then restart phone. When phone is back on, try adding e-mail account again, and be sure you're entering exactly as you set up, meaning its case-sensitive. If you're still getting same error, please let us know and let us know what e-mail account it is, Yahoo, AOL, MSN, etc.
    Thank you,
    VanessaS_VZW
    Follow us on Twitter @VZWSupport

  • Pages for iPad is not recognizing the password I assigned to a document.  I included a hint, and I know I am entering the password that goes with the hint.  Is there anything I can do to access my doc?

    Pages for iPad is not recognizing the password I assigned to a document.  I included a hint, and I know I am entering the password associated with the hint.  Is there anything I can do to access my document?  i quite the Pages app and restarted it.  Now I guess I'll reset the iPad and see if that helps.   Thanks!

    Rhonda Fogel wrote:
    Interesting that one does not need the password to delete using Finder.
    The Pages password protects the contents of the document.  If there were a Finder password, it would protect what you might think of as the "file wrapper" ... the stuff around the file content.
    Glad it's not vital.  I have to say I only pasword protect those Pages documents that are, in fact, vital.
    Best of luck.

  • When trying to log on to my personal hotspot on my Ipone, after entering the password the system continues to ask for the password over and over again. How do I fix this?

    When trying to log on to my personal hotspot on my Ipone, after entering the password the system continues to ask for the password over and over again. How do I fix this?

    Hi SheilaStuhr,
    The troubleshooting steps detailed below can help get you connected to your iPhone's personal hostpot.
    Basic troubleshooting
    See if your iOS device, computer, and wireless plan all meet the system requirements for Personal Hotspot.
    Make sure Personal Hotspot is on: Tap Settings > Cellular > Personal Hotspot.
    Check the Internet connection on your iOS device: Tap Safari and load a new webpage.
    If one connection type doesn't work, try another. For example, instead of connecting using Wi-Fi, use USB or Bluetooth.
    Turn Personal Hotspot off and on: Tap Settings > Personal Hotspot or Settings > Cellular > Personal Hotspot.
    Install the latest version of iOS.
    Reset your network settings: Tap Settings > General > Reset > Reset Network Settings.
    If you still see the issue, restore the iPhone.
    If you're still experiencing issues, try the steps below.
    Wi-Fi troubleshooting
    If you encounter an issue using Personal Hotspot with other Wi-Fi devices, try these steps:
    Turn Personal Hotspot off.
    Turn on Wi-Fi: Tap Settings > Wi-Fi.
    Turn on Personal Hotspot.
    If another device can't join your Wi-Fi network, make sure the Wi-Fi password is correct.
    If the device can't see your Wi-Fi network, check your device name. Windows may not correctly show a device name that uses non-ASCII characters.
    See how many devices are using your Personal Hotspot. Depending on your wireless carrier, the number of Wi-Fi connections may be limited to three devices at once.
    If the other device still can't connect, turn Wi-Fi off and on for the device.
    Make sure that your device can see other Wi-Fi networks.
    Note: If you see "Unable to Join" or a timeout error when you try to connect a device using Wi-Fi, remain on the Personal Hotspot screen until the first device connects. After the device connects, you can leave the Personal Hotspot screen and use your iPhone normally. Your device will stop broadcasting Wi-Fi if you put it to sleep or if 90 seconds elapse and no connected devices use Wi-Fi. To share your Wi-Fi network again, tap Settings > Personal Hotspot.
    iOS: Troubleshooting Personal Hotspot
    http://support.apple.com/en-us/HT203302
    All my best,
    Allen

  • HT4009 I attempted an in app purchase of gems in Clash of Clans.  After entering my password I got a pop up saying "Your purchase could not be completed" & directing me to support at this site.  I have not found anything here that solves the problem.

    I attempted to purchase gems as an in app purchase in Clash of Clans. After entering my password I got a pop up saying the purchase could not be completed & telling me to go to the support page.  My settings allow in app purchases.  Why am I unable to make in app purchases?

    If you are getting a message to contact iTunes Support then you can do so via this link and ask them for help (we are fellow users here on these forums, we won't know why you are getting the message) : http://www.apple.com/support/itunes/contact/ - click on Contact iTunes Store Support on the right-hand side of the page, then Purchases, Billing & Redemption

  • When I want to download a app it says after entering apple password it says connection manager invoke retry or cancel

    I can't download anything
    When I want to download a app it says after entering apple password it says connection manager invoke retry or cancel

    HOLY CRAP!!!!
    been going round this issues for hours....tried every fix i could find
    phones and most of my pcs worked except 1, my main laptop.
    i FIXED IT BY ENABLING GENIUS.!!!!!!!!!!
    only on that laptop though.
    try it.
    i'm so happy right now.
    not gonna turn it back off again yet cos while its working im not touching it again!

  • My ipad is disabled after entering wrong password

    Please help me. My ipad is disabled after entering wrong password. i actually forgot my password and in the course of trying for several times, it became disabled. Please how can i enable and unlock it. I tried connecting to iTunnes on my laptop but the iTunnes could not connect, saying the ipad is locked.
    Please how can i get the ipad back to use.
    Thanks

    I've never set a passcode on my devices. I already have enough of them between work and my mail accounts, FacBook, yahoo, etc. If i ever do and I have a problem, I'll remember that this information is out here...
    Sly

  • On my login page where my username is and I enter my password, there is a message someone has put there I'd like to remove, and we can't figure what setting to go to to edit it.  Please help.

    On my login page where my username is and I enter my password, there is a message someone has put there I'd like to remove, and we can't figure what setting to go to to edit it.  Please help.

    it's in system preferences > security and privacy > general > show a message when the screen is locked.

  • IMac is asking for admin login password upon startup when it never did before, settings are still on auto login. Why is it doing this out of the blue?

    iMac is asking for admin login password upon startup when it never did before, settings are still on auto login. Why is it doing this out of the blue?

    Is sounds like it might for some reason booting into Safe Mode, which does prompt for a password.
    Try a PRAM reset:
    Shut down the computer.
    Locate the following keys on the keyboard: Command, Option, P, and R. You will need to hold these keys down simultaneously in step 4.
    Turn on the computer.
    Press and hold the Command-Option-P-R keys. You must press this key combination before the gray screen appears.
    Hold the keys down until the computer restarts and you hear the startup sound for the second time.
    Release the keys.
    If that doesn't help, restart holding down the option key which should take you to the startup manager. Select Macintosh HD (you may need to use the arrows on the keyboard if the kb is Bluetooth), tap 'enter'. Does it boot normally now?

  • HT1498 After entering my password a message comes up that says I can only use this account in th US and returns to sign in screen. I am I the uS . Am I missing something?

    After entering my password a message says I can only use account in US. Then returns me to sign in page. How do I rent a movie?

    After a great deal of searching I ran across the suggestion to disable all plug-ins and then, one by one, enable them until finally the problem was solved. I am not sure which plug-in was causing the problem, as I am satisfied to have the problem solved. I am going to leave the rest of the plug-in disabled.

  • IPad locked by entering incorrect password multiple times. how do i reset the iPad 1.0

    iPad locked by entering incorrect password multiple times. how do i reset the iPad 1.0

    See this article : http://support.apple.com/kb/HT1212

  • My iphone 5s got stolen and the option to erase data after 10 tries was not enabled. What happens after the incorrect password is input after 10 times?

    my iphone 5s got stolen and the option to erase data after 10 tries was not enabled. What happens after the incorrect password is input after 10 times?

    After the sixth erroneous passcode entry a delay is imposed that increases exponentially and eventually reaches over 40 years before another attempt can be made.
    No one yet knows how long the next delay is.

  • I have a Galaxy S5 with Global International plan in place. My txt to Jamaica are not being received there, but others are. Is there a setting in my phone I need turned on? Verizon customer service doesn't have any answers.

    I have a Galaxy S5 with Global International plan in place. My txt to Jamaica are not being received there, but others are. I can receive the messages, but not send. I get an msg saying, message to (my daughters number) failed: Network problem. Is there a setting in my phone I need turned on? Verizon customer service doesn't have any answers.

    Hello ffdaisy!  I sure hope you're having a great time in Jamaica! I'm so sorry about your messages. Let's get going on a resolution! to clarify, are you able to receive messages? Can you send to the states, but not to numbers originating in Jamaica?  First, I want to let you know how to get in touch with our Global Support Team while outside the US. Just click here for the information: http://vz.to/18oaptS   Second, I'd like to provide you with the dialing pattern for messaging to US numbers, and Jamaica nunbers. For the US, dial 1, then the area code, then the 7-digit number. for Jamaica numbers, dial area code 876, then the 7-digit number. For more information, click here: vzw.com/international   Thanks so much, and have a great trip! ChristinaB_VZW Follow us on Twitter @VZWSupport If my response answered your question please click the "Correct Answer" button under my response. This ensures others can benefit from our conversation. Thanks in advance for your help with this!!

  • Can i activiate my new iphone4s with a different computer that i activated my first iphone with as long as i'm using my itunes account?

    can i activiate my new iphone4s with a different computer that i activated my first iphone with as long as i'm using my itunes account?

    I sync my iPhone with my MacBook Pro.
    I installed the 3.1.2 firmware update today with a PC laptop running Vista that I haven't synced my iPhone with. I made sure the Windows laptop was running the current iTunes version, and before connecting my iPhone, I disabled automatic syncing when any iPod or iPhone is connected which is done via iTunes preferences under the Devices tab.
    I took a risk and didn't create a backup for my iPhone when prompted. The firmware update followed by installing the AT&T carrier update was done without a hitch.
    This is risky without having a backup (which I could have done beforehand) and without having any of my iTunes content available on the PC if there was a problem installing the update.
    Do the same at your own risk. The worst would be not having any iTunes content to transfer back to your iPhone in the event you needed to restore your iPhone with iTunes on a different computer but if you allow iTunes to create a backup for your iPhone in advance, at least you could restore your iPhone from your newly created iPhone backup in the event of a problem.

Maybe you are looking for

  • K7n2 with a serial ata addin card

    I have a k7n2 without the serial ata controller, athlon 2400, 512 mb ddr 333, and a winfast geforce 2 mx 64.  my question is will i be able to boot off of an addin serial ata card and a western digital raptor 36 gig hard drive.  also will the bios be

  • Fill a combo box based on the selection of another combo box

    Hi All, I am new to jsp & java script. I have a arraylist of communities and there are 2 combo boxes meant for source community & destination community. First user will select Source community , after that I've to remove that community from list and

  • How do i get around the A12E1 error for installing application mgr

    how do I get around the A12E1 error

  • Nfs + zfs on linux

    How do you use nfs + zfs on linux? I vaguely remember that there was some nfs functionality built into zfs, but i'm not sure if that works on linux also. Currently i am using the standard nfs export method described in the wiki, which has the problem

  • SRS Auto log out time

    Hi My Client is using  SAP Retail Store SRS ,the users are complaining that the SRS web page (gui) time out is very less. Where can i set SAP SRS auto logout parameter. Thanks Sridhar