Office 365 AAD Password Writeback not working; Event Viewer Error: 0x80230619 (A restriction prevents the password from being changed to the current one specified.)

Hello all,

I'm currently setting up a Proof Of Concept setup with directory synchronisation and password syncing to Office 365, leveraging AAD Premium for the password reset and password writeback to on premises AD functionality. Directory Sync + Password Sync is working flawlessly with the AADSync tool. However, upon requesting a password reset for a user, I'm hitting a password writeback error. The webpage states that the password does not meet the password complexity policy, while it does. I can set that particular password for that account at the on premises AD without any problem.

In the event viewer at the AADSync server, I'm seeing this Error pop up whenever I try to reset the password:

An unexpected error has occurred during a password set operation.  "BAIL: MMS(4032): ..\server.cpp(11003): 0x80230619 (A restriction prevents the password from being changed to the current one specified.) Azure AD Sync 1.0.0475.1202"

My Setup:

  • Windows Server 2012 AD with a single forest
  • Seperate domain joined Windows Server 2012 for AADSync tool
  • AADSync version 1.0.0475.1202 with options password sync, password writeback enabled
  • Service account for AADSync tool with Replicating Directory Changes and Replicating Directory Changes All permissions on root AD forest structure with inheritance to all objects. This account also has the permissions to Change Password and Reset Password on all descendant User Objects.
  • AAD Premium for my office 365 tenant
  • AAD Premium licenses for the test users and the office 365 account used to sync to Office 365. This account is also Global Admin.

Could anyone help me with this? Is there something Im missing here? My guess is that the AAD is not trusted or the service account for AADSync tool does not have the proper permissions. Ive tried many options, like setting the AADSync Service account to Enterprise Admin or granting the service account Full Control over that particular user.

December 23rd, 2014 10:21am

Concerning my issue:

The Default Group Policy setting: Minimum Password Age is set at 1 day. As I was testing this feature with new users, their provisioned passwords were less than 24 hours old and the Minimum Password Age of 1 prevented the change of the password.

After changing this to 0 days in the Default Group Policy, my password resets started working for newly created users. While this might not have affected existing users in production, it had me looking and searching for permission issues on my AD.

So for those that might be experiencing ADSync Event ID 6329 and PasswordResetService Event ID 33008 Errors when trying to do a Password Reset using AAD Premium with Password Writeback, it might be helpful to check the applied password policy.

The issue is solved.

  • Marked as answer by Tim Wolfers Tuesday, December 23, 2014 2:46 PM
Free Windows Admin Tool Kit Click here and download it now
December 23rd, 2014 2:46pm

Concerning my issue:

The Default Group Policy setting: Minimum Password Age is set at 1 day. As I was testing this feature with new users, their provisioned passwords were less than 24 hours old and the Minimum Password Age of 1 prevented the change of the password.

After changing this to 0 days in the Default Group Policy, my password resets started working for newly created users. While this might not have affected existing users in production, it had me looking and searching for permission issues on my AD.

So for those that might be experiencing ADSync Event ID 6329 and PasswordResetService Event ID 33008 Errors when trying to do a Password Reset using AAD Premium with Password Writeback, it might be helpful to check the applied password policy.

The issue is solved.

  • Marked as answer by Tim Wolfers Tuesday, December 23, 2014 2:46 PM
December 23rd, 2014 2:46pm

Hi Tim,

Thanks for your sharing solution and idea.It will be very beneficial for other community members who have similar questions. If you have any difficulty in future programming, we welcome you to post in forums again.

Regards,

Will

Free Windows Admin Tool Kit Click here and download it now
December 24th, 2014 6:03am

Thanks for the solution, worked for me!

Regards, Marcel

July 20th, 2015 10:40am

Thanks for the solution, worked for me!

Regards, Marcel

Free Windows Admin Tool Kit Click here and download it now
July 20th, 2015 2:38pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics