Windows AD account password expired but user can still send/receive email and use Teams.

fnanfne 1 Reputation point
2022-09-08T16:57:18.027+00:00

Hi.

I recently discovered that some users with expired AD passwords are still working as if nothing has changed, which caught me by surprise. All the users affected do not use the VPN on a regular basis, or sign into Office 365. They all use desktop office for their email (Outlook) and chats (Teams). We are all still working from home.

It seems that a user is only challenged to update their expired password once they physically authenticate against the domain controller(s). But what if they never do? This means a user with an expired password will continue to send/receive emails and send chats in Teams regardless of when their password expired, unless they perform a "logon".

I ran a PowerShell script to elucidate more and found that we have dozens of users in this boat. Some users have passwords that expired YEARS ago!

Is this by design? In that the password expiration field is pointless until said account actively connects to the domain? Why is the "expiration" field/property not part of the user SID? I'm baffled.

We have on premise domain controllers which syncs out to Office 365 via ADSync.

Any help appreciated.

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Windows for business | Windows Server | User experience | Other
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Anonymous
    2022-09-08T17:36:29.157+00:00

    Sounds like sync may be broken. The product group for Office 365 actively monitors questions over at
    https://techcommunity.microsoft.com/t5/office-365/ct-p/Office365

    --please don't forget to upvote and Accept as answer if the reply is helpful--

    1 person found this answer helpful.
    0 comments No comments

  2. fnanfne 1 Reputation point
    2022-09-08T18:28:59.59+00:00

    HI DSPatrick

    I have run all diagnostics I could find and sync appears to be working just fine. I can also see on Office 365 that ADSync regularly syncs (including password sync).

    Thanks, I'll ask over on the Tech Community forum as well.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.