User unable to Authenicate to AD after password change [Random]

Answered User unable to Authenicate to AD after password change [Random]

  • Monday, December 03, 2012 9:47 PM
     
     

    Hi,

    Some users in our environment has issue logging in to domain resource after changing password.

    If Administrator update the password using ADUC, back to the original password they were using. Problem resolved.

    I looked at our Domain Controller, there was no AD replication issues. The only issue I found was Memory leak of MMC on our PDC. (Win2k8R2).

    I transfer all the Domain roles (PDC, RID and Infrastructure) to another DC and restart the server. Problem still exist to some users.

    I am not sure where to look at next... Any idea?

    Thanks

All Replies

  • Tuesday, December 04, 2012 1:19 AM
     
     Answered

    It seems that the health of Dc's is not good.What error message you are recieving while login to server.Can you post the dcdiag/q ,repadmin /replsum and ipconfig /all details of DC.Also one of the problematic clients ipconfig details.

    Since the PDC role is move ensure that authorative time server is configured
    Configuring the time service on the PDC Emulator FSMO role holder
    http://msmvps.com/blogs/acefekay/archive/2009/09/18/configuring-the-windows-time-service-for-windows-server.aspx

    For other domain computers / servers /Dc's, make sure that they are using NT5DS for time sync. More here: http://support.microsoft.com/kb/223184


    Best Regards,

    Sandesh Dubey.

    MCSE|MCSA:Messaging|MCTS|MCITP:Enterprise Adminitrator | My Blog

    Disclaimer: This posting is provided "AS IS" with no warranties or guarantees , and confers no rights.

    • Marked As Answer by MoMo79 Thursday, December 06, 2012 7:26 PM
    •  
  • Tuesday, December 04, 2012 8:48 AM
    Moderator
     
     Proposed Answer

    Hi,

    Have a look at below KB:
    Users Cannot Log On to the Domain After Password Changes on a Remote Domain Controller
    http://support.microsoft.com/kb/318364

    Regards,
    Cicely

    • Proposed As Answer by VenkatSP Tuesday, December 04, 2012 2:09 PM
    •  
  • Tuesday, December 04, 2012 10:44 AM
    Moderator
     
     

    Hi,

    Some users in our environment has issue logging in to domain resource after changing password.

    If Administrator update the password using ADUC, back to the original password they were using. Problem resolved.

    I looked at our Domain Controller, there was no AD replication issues. The only issue I found was Memory leak of MMC on our PDC. (Win2k8R2).

    I transfer all the Domain roles (PDC, RID and Infrastructure) to another DC and restart the server. Problem still exist to some users.

    I am not sure where to look at next... Any idea?

    Thanks

    Is your all DC in windows 2008 R2 is running with latest updates, patches & fixes, if not that is the first thing I'll do it. There is no network or firewall issues.

    http://support.microsoft.com/kb/2386717

    What does DCDIAG actually… do?  http://blogs.technet.com/b/askds/archive/2011/03/22/what-does-dcdiag-actually-do.aspx


    Awinish Vishwakarma - MVP

    My Blog: awinish.wordpress.com

    Disclaimer This posting is provided AS-IS with no warranties/guarantees and confers no rights.