Account getting locked out

tytran
New Contributor

Has anyone run into this issue:

-MacBooks are bound to AD

-User changes password.

-Restarts/locks computer can't sign back in again.  States account is locked out for "15 minutes"

-Log in as the local Administrator account and log back out, user can then sign in without issue.

-Change user's password and they can log in but when they restart/shutdown, won't let them back in until we sign in as local admin account.

 

7 REPLIES 7

jmcfarland
New Contributor

We have been having some consistent issues related to authenticating and login related to secure token. I have no explanation as to why this is happening but turning off and on secure token has consistently resolved ours. Right now we are just using a comman in terminal and don't have anything scripted. We are using MBA M1s. Suspect it has to do with keychain. I would first confirm time and bind are good though.

What is the command you are using? Can you provide it?

We use

sysadminctl interactive -secureTokenOff userneedingtoken -password -

sysadminctl interactive -secureTokenOn userneedingtoken -password -

first prompt window will be for your local account that has a token then the second prompt in terminal will be for the users password

obi-k
Valued Contributor II

Sounds like the FileVault password isn't updated. Are you using Apple Kerberos or Jamf Connect to sync password?

 

https://community.jamf.com/t5/jamf-pro/a-reliable-fix-for-filevault-2-password-sync-issue/m-p/306052

AJPinto
Honored Contributor II

Apple stopped developing macOS with domain binding in mind some 10 years ago. The number of issues with domain bound workflows is constantly increasing and will continue to do so.

 

How exactly are your users changing/syncing their passwords? Sounds like FileVault is not syncing their new passwords.

tytran
New Contributor

System Settings - User & Groups - click on their username - Change... 

gesiyeIgbas
New Contributor II

My organization's environment also has this issue when our users' passwords expire. We have them set up in Active Directory, and when the login page is supposed to allow them to reset their password when it expires, but recently, they won't be able to use the changed password. we have to set their password remotely and then make the user change it via NoMAD.