Skip to main content
markdr_FTNT
Staff
Staff
July 27, 2025

Troubleshooting Tip: After changing a password, the user can still use the old password

  • July 27, 2025
  • 0 replies
  • 369 views
Description This article describes a scenario where changing a user password in LDAP via FortiAuthenticator may still permit the user to log in with the old password.
Scope FortiAuthenticators are integrated with Windows Active Directory.
Solution

FortiAuthenticator can be configured to permit LDAP users to change their password; however, it may be seen that after a user's password has been changed, that it is still possible to log in with the old password as well as the new one.

 

The reason for this is likely related to the default behavior of the Windows NTLM network authentication (and not the FortiAuthenticator), which permits domain users to use their old password for five minutes after the password is changed.

 

After a domain user successfully changes a password by using NTLM, the old password can still be used for network access for a user-definable period. This behavior allows accounts, such as service accounts, that are logged on to multiple computers to access the network while the password change propagates.
To change the lifetime period of an old password, a registry setting needs to be created on the domain controller.

 

The behavior and a workaround are described in: https://learn.microsoft.com/en-us/troubleshoot/windows-server/windows-security/new-setting-modifies-ntlm-network-authentication.

To change a user password in LDAP, the user can log in to the self-service user portal

 

There are specific configuration requirements for FortiAuthenticator to support changing of password.

 

Related documents:

FortiAuthenticator LDAP configurations

Technical Tip: Requirements for user password change with FortiAuthenticator as user database

Technical Tip: How to allow an LDAP user to change password at first logon or renew an expired passw... as RADIUS server

    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!