Syncing Force Password Change at Next Logon from local AD to AAD

Corey Shanks 31 Reputation points
2021-02-04T16:50:13.993+00:00

I can't seem to sync across the force password change at next logon flag from my local AD to AAD. I am using Azure AD Connect and have followed several guides on how to set this up. I have SSPR and Password Writeback enabled. I have also set the ForcePasswordChangeOnLogon to true as followed here in this guide: https://blog.naglis.no/?p=3923. I have also run through the Azure AD Connect product and ran a configuration again to see if that would help sync across the password change flag. Is there anything else I am missing? Any help would be greatly appreciated!

Also forgot to include that I have Password Hash Synchronization enabled as well.

Microsoft Security | Microsoft Entra | Microsoft Entra ID
{count} vote

Accepted answer
  1. Andy David - MVP 157.8K Reputation points MVP Volunteer Moderator
    2021-02-04T18:08:28.743+00:00

    The force password change in of itself is not synced, you have to also set a temporary password on-prem. Are you doing that?
    https://learn.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-password-hash-synchronization#synchronizing-temporary-passwords-and-force-password-change-on-next-logon

    64018-image.png


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.