Users cannot change their password on WS2012R2 domain

windows-server-2012-r2

I have just made a new Windows Server 2012 R2 domain. Joined the PC and user to the domain and everything Works on that end.

Now I made a group policy (that is being checked as being pushed with rsop.msc on the client PC) that allows them to put any password they want.

The problem is that the clients (via Ctrl+Alt+Del) cannot change their password. It gives them the error message of

Unable to update the password. The value provided for the new password does not meet the length, complexity, or history requirements of the domain.

I've gone also to the "Default Domain Policy" and tried to change it there (even though rsop.msc says that the GPO being applied is the one I made) and it still does not allow them to change it.

I also joined a fresh machine and a new user, and it still does not apply. I have it set to apply to all authenticated users. Do I need to change something else?

A few other things:

The OU (Computers) that my GPO is linked to is all computers. My OU is "Company Name" and inside of it there are two other OUs One is "Users" and the other is "Computers". I am only linking it to Computers.

gpresult /r is telling me that the policy is being applied to the computer.

I am doing gpupdate /force on both server and client side (should not be neccesary for client)

Best Answer

There can be only one password policy per domain and it MUST be linked to the domain. A password policy linked to an OU will have no effect. The GPO may show as being processed but the settings will not be implemented. - http://blogs.technet.com/b/askpfeplat/archive/2013/01/14/fun-and-games-active-directory-password-policies.aspx