Version Affected: All
Overview
When using the Enforce Password Change Requirement setting, after a user changes their password, an InvalidOriginalPassword error appears. Neither the original password nor the new password works afterward.
Cause
Enforce Password Change Requirement sets two passwords in Active Directory during a password change: a randomly generated password and the new password the user is setting. The randomly generated password is set so the Identity Platform (IdP) can verify the new password meets complexity requirements. This causes the InvalidOriginalPassword error if the realm's connection string is not pointed to the primary Domain Controller (DC).
To resolve this, change the realm's connection string to point to the primary DC, instead of the domain's fully qualified domain name (FQDN).
SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.
Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.
Comments
Please sign in to leave a comment.