Unable to change domain password even if the password is complex

active-directorypasswordpassword-managementwindows-server-2012-r2

I have a problem with users not being able to change their passwords.

When they try to change the password, they get this error:

"Your new password does not meet the length, complexity, or history requirements of your domain. Try choosing a different new password."

However, the password is definitely complex (20+ chars randomized numbers letters symbols etc), is not within hold period of one day.

The user has the permissions to change their password as you can see below:

enter image description here

I really don't see what could be the problem. Any tips?

Best Answer

This is probably because the password is too similar to one of the previous ones that are held in the history. Switch that option off and see what happens. It can be manipulated using the group policy editor (gpedit.msc).

Related Topic