Score:0

Local administrator tagged "must change password" when domain user joins azureAD using OOBE

mx flag

Hi all thanks in advance and sorry if my question is not properly structured, first time I ask instead of just lurk:

  • I have a hybrid on-prem/azureAd environment using dirsync
  • Laptops are imaged with a local administrator account with psswd set to "never expire"
  • Users go through OOBE and join azureAD

After this, the "Administrator" account is disabled - Default windows10 behaviour, OK.

THIS IS MY ISSUE - The extra local administrator gets the flag to "user must change password on next logon" set to true.

If you log in using audit mode before OOBE or finish OOBE with a local "offline" account, this does NOT happen.

I can't for the life of me find where in the domain policy this is getting pushed.

I see nothing useful doing an Rsop / GpResult...

Jevgenij Martynenko avatar
us flag
See if this can answer your question https://www.reddit.com/r/Intune/comments/gzwru3/local_administrator_account_user_must_change/fwdj9jx/
Score:0
in flag

This is default and expected behavior. You should avoid having the local admins burnt into image or provisioned with permanent static password.

Since you are in Hybrid mode, and according to best practices, please consider implementing LAPS (https://techcommunity.microsoft.com/t5/itops-talk-blog/step-by-step-guide-how-to-configure-microsoft-local/ba-p/2806185) on your on-prem Windows Server Active Directory, that can regularly update and maintain local admin passwords to your on-prem Windows Server Active Directory.

mangohost

Post an answer

Most people don’t grasp that asking a lot of questions unlocks learning and improves interpersonal bonding. In Alison’s studies, for example, though people could accurately recall how many questions had been asked in their conversations, they didn’t intuit the link between questions and liking. Across four studies, in which participants were engaged in conversations themselves or read transcripts of others’ conversations, people tended not to realize that question asking would influence—or had influenced—the level of amity between the conversationalists.