Issues with First Logon to AAD Joined Device

0
4
Asked By CuriousCow794 On

I'm dealing with a situation where a newly synced Active Directory user has the flag set to change their password at the next logon, but they're trying to log in to an Azure Active Directory (AAD) joined machine for the first time. They're attempting to access Office.com, but it's failing. We have Self-Service Password Reset (SSPR) configured and it works for other users. The setting for "ForcePasswordChangeOnLogOn" is currently set to false. Should I change this to true, and do we need to configure anything on the AD account before making that adjustment?

4 Answers

Answered By CuriousCow794 On

Yes, password write-back is enabled and it works fine for regular users.

Answered By SystemsGuru911 On

Just to follow up, do you have password write-back enabled? That could affect whether the password change process works for this user.

Answered By QuestionAsker99 On

I got some additional details. The user actually can't log into their AAD joined workstation at all. Do you think changing the "ForcePasswordChangeOnLogOn" setting will resolve this? And will it force a password change for all users or just new ones?

Answered By TechSavvyStar029 On

Have you checked the sign-in logs for any specific failure reasons? It could be related to SSPR and whether MFA registration is complete for the user. Knowing that info could really help narrow down the issue.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.