Domain Admin account entered at elevated privelage prompt authenticates with expired password.


a user brought issue attention , hoping clarification on it.

on our server 2008 r2 domain, user domain admin account expired password able pass authentication while running elevated commands on remote servers.

he logs onto remote server first separate service account. then, while logged on service account, attempts run service administrator.  enters domain admin account **which has expired password** , passes authentication.

does have explanation why possible?  normal function on windows servers?

i expect user expired password need change password before being able pass authentication @ uac prompt.

thanks!

hi,

i didn't find official document this. tested in lab , got same result you.

logon , runas command not work. uac still accepts credential.

best regards.


steven lee please remember mark replies answers if , unmark them if provide no help. if have feedback technet support, contact tnmff@microsoft.com.



Windows Server  >  Security



Comments

Popular posts from this blog

Error: 0x80073701 when trying to add Print Services Role in Windows 2012 Standard

Disconnecting from a Windows Server 2012 R2 file sharing session on a Windows 7,8,10 machine

Windows 2016 RDS event 1306 Connection Broker Client failed to redirect the user... Error: NULL