Password Change Logon Loop

Robert Pearson 31 Reputation points
2022-03-29T12:46:34.103+00:00

Hello, I have this issue when users passwords expire or I manual reset them with "User must change password" box checked. Every time they enter a new password it tells them to do it again in an endless loop. Any ideas?

We have two DC's with Server 2019 and one DC with 2012.

We do do AD SYNC to Azure

PCS are mostly Windows 10 with a couple Windows 11

Thanks

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,524 questions
{count} votes

6 answers

Sort by: Most helpful
  1. Robert Pearson 31 Reputation points
    2022-03-29T13:37:07.96+00:00

    Uninstalling KB5011551 from my DCs resolved the issue. Thanks

    3 people found this answer helpful.

  2. CRoth2 36 Reputation points
    2022-04-14T16:46:13.287+00:00

    April update KB5012647 build 17763.2803 says, "Improvements: Addresses an issue that prevents you from changing a password that has expired when you sign in to a Windows device." I have installed the update on my DCs and restarted and confirm that I am now able to reset a user's password when "User must change password at next login" is checked. I did not test an expired user since I didn't have one, but that should be resolved also.

    https://support.microsoft.com/en-us/topic/april-12-2022-kb5012647-os-build-17763-2803-9a10c5c9-e65f-4ae1-a9c4-2db9a8eca4fc

    1 person found this answer helpful.

  3. Marcus Polz 1 Reputation point
    2022-04-01T16:18:38.403+00:00

    I experienced the password loop with users after a March 22nd update. We are on 2 AD Windows 2019 1809 Standard WinVer 17763.2746. We do AD SYNC to Azure as well. We see the issue occur upon expiration of a user password or when ticking the box to have user change password at next logon. No unusual event logs were observed. You can test by expiring a user account, the next login attempting to change password loops. The uninstall of Microsoft update KB5011551 takes a scary long time to remove, it completed in about twenty minutes. It does require a reboot of the server which also takes about thirty-forty minutes, I'd suggest staggering reboots of the DCs :).

    Verified, removal of KB5011551 resolved my password issues.

    0 comments No comments

  4. sławomir wowry 1 Reputation point
    2022-04-02T09:31:44.863+00:00

    The question is when Microsoft will release a patch
    We have several DC controllers in the organization
    and uninstalling KB5011551 will take a long time


  5. Pflipper 96 Reputation points
    2022-04-04T23:46:05.983+00:00

    I have the same endless loop issue with an expired password on a domain Admin account for an Azure vm. Microsoft needs to fix this ASAP. Have this KB5011551 installed on 3/26, I come back from time off and now I am hosed.

    BTW, I tried to uninstall the hotfix through Powershell in the Azure portal. This does not work - why ? --> C:\Windows\System32\wusa.exe /uninstall /kb:5011551 /quiet /norestart


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.