Article ID: 258788 - Last Review: January 27, 2007 - Revision: 2.3 Cannot Change Password in Windows Without Logging on to DomainThis article was previously published under Q258788 SYMPTOMS
If a password policy is being used in a Windows 2000 domain and some or all of the users in the domain were migrated to Active Directory by using the Active Directory Migration tool, users who attempt to change their password after receiving the "Password Change Notification" message may receive the following error message:
You do not have permission to change your password.
CAUSE
This behavior occurs if the Everyone group has not been granted the Change Password right on the user object. By default, the "Password Change Notification" message appears 14 days before the "Maximum password age" policy setting. If the Everyone group does not have the Change Password right on the object, passwords cannot be changed over the null session connection (anonymous logon relies on the Everyone group to carry out this action) established between the workstation and a domain controller. Instead, an authenticated session is required to change a password (users must be logged on to change their password). RESOLUTION
To resolve this issue:
STATUSMicrosoft has confirmed that this is a problem in the Microsoft products that are listed at the beginning of this article. APPLIES TO
| Article Translations
|

Back to the top
