Skip to main content
Solved

Active Directory Domain member - Computer-Account: Maximum machine account password age


Forum|alt.badge.img+8

All Macs are bound to our AD (Windows2012R2) by Casper (9.61)
I see some Mavericks clients loosing the ability to contact the AD. Error Message is like "Cannot contact the Domain Controller". Rebinding helps. But what's the cause? I am suspecting the default 30 days windows policy setting for the maximum allowable age for a computer account password: http://technet.microsoft.com/en-us/library/jj852252(v=ws.10).aspx
Did anyone investigate that further? Or is it irrelevant for OSX ?
Thanx a lot!

Best answer by calumhunter

Have a chat to your AD admin. Perhaps they have a policy of removing machines from AD or disabling them if they have not updated their machine password in x days.
Do you have any read only domain controllers?

View original
Did this topic help you find an answer to your question?

Forum|alt.badge.img+10
  • New Contributor
  • December 2, 2014

Have a chat to your AD admin. Perhaps they have a policy of removing machines from AD or disabling them if they have not updated their machine password in x days.
Do you have any read only domain controllers?


davidacland
Forum|alt.badge.img+18
  • Valued Contributor
  • December 3, 2014

In the past I have set this to 0 on the client side (dsconfigad -passinterval 0) particularly for laptop users who were out of the office (and out of contact from a DC) for extended periods of time.

As Calum says, it is really a question for your AD admin, although I've never heard of anyone changing this value on the Windows server side.


Forum|alt.badge.img+8
  • Valued Contributor
  • December 3, 2014

Thanx a lot. You were both right - awesome! There is a GPO on the Windows-side that did "clean" up. And of course the 14 days set for password interval were to short for the laptop users! Thank you!



Cookie policy

We use cookies to enhance and personalize your experience. If you accept you agree to our full cookie policy. Learn more about our cookies.

 
Cookie settings