Using Classic Outlook on Windows for personal email, calendar, and contact management
Hello Brent,
Please feel free to share with me if you got any further updates, thanks.
Best Regards,
Oliver
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Hello,
I am having an issue with a hybrid Exchange server. After an active directory user changes their AD password, the first time they open Outlook (and enter their new AD password), the hybrid Exchange server causes their AD account to lockout. No mailboxes are stored on the hybrid server. Outlook functions correctly, but the AD account is locked out until the lockout time limit is reached. It is almost like the hybrid Exchange server is hanging on to the users old password rather than using the new one. Any thoughts?
Using Classic Outlook on Windows for personal email, calendar, and contact management
Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.
Hello Brent,
Please feel free to share with me if you got any further updates, thanks.
Best Regards,
Oliver
Hello Brent,
Based on the information you shared, my understanding is you deployed Azure AD and AD password policies for the failed logon attempts allowed x then cause the account lockout, also you are using Password Hash Sync in the tenant, please clarify if I misunderstand your scenario, thanks.
If so, may I double confirm if the user wait some minutes then try the new password in Outlook with cloud mailbox? As the password hash sync would take every 2 minutes to sync the ( new )password from local AD to Azure AD and stored there with Hash, if the user try the new one immediately, the new password may not synced to Azure AD yet, and it may still only recognize the old password, once the user try one more times ( based on your password policy) with failed logon, then the local AD account may be locked. For your reference Implement password hash synchronization with Azure AD Connect sync.
Moreover, if you enabled both Azure AD and AD password policy for protection failed or try logon against hackers, it is recommended that please make the failed/try logon allowed times in Azure AD side is lower than the local AD side, as if someone try to login Microsoft 365 with the user account more times failed, if the local AD side allowed failed times is higher than Azure AD side, this would not cause the AD account locked out, and the user would temporarily cannot access Azure AD services for a period time, thanks. For your reference https://docs.microsoft.com/en-us/azure/active-directory-domain-services/password-policy.
Please feel free to share with me if you have any other concern, thanks.
Best Regards,
Oliver