Troubleshooting Tip: After changing a password, the user can still use the old password
| Description | This article describes a scenario where changing a user password in LDAP via FortiAuthenticator may still permit the user to log in with the old password. |
| Scope | FortiAuthenticators are integrated with Windows Active Directory. |
| Solution | FortiAuthenticator can be configured to permit LDAP users to change their password; however, it may be seen that after a user's password has been changed, that it is still possible to log in with the old password as well as the new one.
The reason for this is likely related to the default behavior of the Windows NTLM network authentication (and not the FortiAuthenticator), which permits domain users to use their old password for five minutes after the password is changed.
After a domain user successfully changes a password by using NTLM, the old password can still be used for network access for a user-definable period. This behavior allows accounts, such as service accounts, that are logged on to multiple computers to access the network while the password change propagates.
The behavior and a workaround are described in: https://learn.microsoft.com/en-us/troubleshoot/windows-server/windows-security/new-setting-modifies-ntlm-network-authentication. To change a user password in LDAP, the user can log in to the self-service user portal
There are specific configuration requirements for FortiAuthenticator to support changing of password.
Related documents: FortiAuthenticator LDAP configurations Technical Tip: Requirements for user password change with FortiAuthenticator as user database Technical Tip: How to allow an LDAP user to change password at first logon or renew an expired passw... as RADIUS server |
