Can't reset password for 1 user on a Windows2016 server (Solved)


  • For over a week when I try to reset the password for one user I get an error:

    "The supplied user buffer is not valid for the requested operation."

    It doesn't matter how I try to reset the password; from ADUC or cmd prompt using net user <samacocuntname> password, or using dsquery and dsmod ) its always the same error. another user in the same OU does not have this problem. I only have one user with this problem.

    I have checked the permissions to the account object, these are identical to a user that does not have this problem.

    It does not matter if I try to reset the password with RSAT from a win2012 R2 machine, it resulted in the same problem.

    This domain only has 2016 domain controllers, functional level is still 2012 R2.


    I promoted a windows 2012 R2 server to DC, and reset the password form that server. This worked, I don't know why.

    Is this a bug in 2016 DC?

    kind regards,


    Tuesday, February 21, 2017 8:19 AM

All replies

  • Hi,

    Good to hear that you have solved this issue by yourself. In addition, thanks for sharing your solution in the forum as it would be helpful to anyone who encounters similar issues.

    Regarding your situation, we cannot confirm this is a bug in Windows Server 2016 DC since it only affect one specific user and currently we have not received similar feedbacks from other customers.

    If there is anything else we can do for you, please feel free to post in the forum.

    Best Regards,

    Alvin Wang

    Please remember to mark the replies as answers if they help.
    If you have feedback for TechNet Subscriber Support, contact

    Wednesday, February 22, 2017 10:19 AM
  • We have had the same problem changing password on one single user on two different Windows 2016 DCs (2008R2 level). Solved by changing the password on one of the Windows 2008R2 DC we still have.
    Monday, May 8, 2017 8:24 AM
  • I'm having the same issue with one of my users. Unfortunately I cannot use a non-2016 DC since my domain is at 2016 functional level.

    Anyone have any ideas?

    Monday, June 12, 2017 2:08 PM
  • Exact same issue, except we are at 2016 Forest and Domain level. One user (for now) where we cannot reset the password:

    Error message

    Wednesday, June 21, 2017 8:34 AM
  • Hi,

    I have same problem and one question:

    After changing the password for user on promoted DC WS2012R2, can the user password change on DC with WS2016?



    Monday, July 3, 2017 8:47 AM
  • Got same issue and same configuration, only 2016 DCs... did you find a way around this???
    Thursday, July 20, 2017 4:32 AM
  • Thanks Sander!

    We had the same issue with a single user (so far).  We updated our DCs to Server 2016, still with functional level 2012 R2. Luckily, one 2102 R2 DC had not been demoted yet.  I was able to log into it and reset the user's password.    

    Thursday, August 3, 2017 7:38 PM
  • Thanks to everyone on this thread. We have just had this problem as well, and fixed it as descxribed above, by setting up a new 2012R2 DC and resetting the user's password from it. There clearly is a bug in 2016

    Thursday, August 10, 2017 10:26 AM
  • Now that there are multiple users reporting this issue, can you confirm this bug? Is there anywhere else this can be reported in order for Microsoft to notice it?
    Monday, August 14, 2017 6:40 AM
  • Just saw the same issue here in a mixed domain.  Password could not be changed from a 2016 domain controller.  Changing it from a 2008R2 domain controller worked.  Once we did that, we could then change it from the 2016 domain controller.

    Friday, August 18, 2017 4:49 PM
  • Monday, August 21, 2017 12:23 PM
  • This looks promising. Will apply this during next maintenance window.
    Monday, August 21, 2017 12:28 PM