Best Practice For Windows System User to change AD Password
Use Windows built-in password change feature. You must be able login to your Windows Computer:
Requirements:
Steps:
- Able to login to your Windows computer - If you are not connected to the lab network with a ethernet cable or the lbnl-employee WiFi, you must connect to the lab VPN first
Login to the computer with your AD credential
Click ctrl+alt+del on the keyboard and select Change a Password
Type in your current AD password and pick your new AD password
ONLY use AD Management tool if step 1 does not work, AD password expired or forgotten
Under the Password Expires column, click on Set for the account that you want to reset the password for
3
Create a password that meets the requirement. Make sure to type the same password again in the Repeat password field
4
Click Set Password
5
You will get a message saying "Your account password has been set"
Follow this instruction if you need to create an AD service account.
Create a new AD service account
Most LBL staff have an AD service account that was created when they were hired. This tool is only used to request additional accounts under limited conditions. If you don't know if you need it, you probably don't.
1
Go to https://adaccounts.identity.lbl.gov and login using your Berkeley Lab Identity credential. Once logged in, click on "Add a new account" on the bottom left of the page
Enter the two sponsor for the AD account, one in each field. You can search for the sponsor by using their name or username
Add the sponsor by typing the first name, last name or username.
5
Create a new password that meets the requirement. Make sure to type the same password again in the Repeat password field
6
Click Create
7
You will get a message on the top saying "Your account "username" was created"
For some AD account types, you will need to wait for OU Admin to assign the correct permissions and move the account to the correct OU before the account becomes accessible. Email your OU Admin and provide them your LBL AD account and the account you just created so they can help process the request. If you do not know who your OU admin is, email help@lbl.gov with your LBL AD account and the account you just created.