Stop Windows Domain Environment Caching Old Passwords?

Posted by Daryl Gill on Server Fault See other posts from Server Fault or by Daryl Gill
Published on 2012-12-14T03:28:03Z Indexed on 2012/12/14 5:05 UTC
Read the original article Hit count: 497

Filed under:
|

I have noticed on my domain environment; the old Administrator password (before password expire).. The client machines have cached the old password and have the ability to bypass the new password by entering the old one..?

I have noticed on my domain environment; the old Administrator password (before password expire).. The client machines have cached the old password and have the ability to bypass the new password by entering the old one..?

Basically; I'm running a UAC enabled domain, which needs the administrator password to continue basic stuff; installations and such. The password for the administrator account has been changed due to expiration of said accounts password. By accident a fellow administrator typed the old password and still bypassed the UAC with what should have been the incorrect password.

Is this a bug with the environment? or something that needs to be tweaked in the server sided settings?

Is this a bug with the environment? or something that needs to be tweaked in the server sided settings?

© Server Fault or respective owner

Related posts about windows-server-2008

Related posts about cache