You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

.NET Core 6重置Active Directory用户密码遇密码策略异常求助

.NET Core Web API重置AD密码时遇到密码策略错误(0x800708C5)的排查方案

我正尝试通过.NET Core Web API重置Active Directory用户密码,但始终返回如下异常,就算用复杂度极高的密码也无法解决:

System.DirectoryServices.AccountManagement.PasswordException:
'The password does not meet the password policy requirements.
Check the minimum password length, password complexity
and password history requirements. (0x800708C5)'

我试过DirectoryEntry和UserPrincipal两种实现方式,结果都报同一个错,代码如下:

public bool ResetPassword(string oldPassword, string newPassword, string userNameI)
{
    /*  // set up domain context
    PrincipalContext context = new PrincipalContext(ContextType.Domain, LDAP_PATH, userName, password);

    if (context != null)
    {
        // find the user you want to delete
        UserPrincipal user = UserPrincipal.FindByIdentity(context, IdentityType.SamAccountName, userNameI);

        if (user != null)
        {
            user.Enabled = true;
            user.ChangePassword(oldPassword,newPassword);
            user.ExpirePasswordNow();
            user.Save();

            return true;
        }
    }*/

    /*  
    var entry = new DirectoryEntry
                    {
                        Path = "LDAP://MyIP",
                        Username = userName,
                        Password = password
                    };

    using (var searcher = new DirectorySearcher(entry))
    {
        searcher.Filter = "(SAMAccountName=" + userNameI + ")";

        var result = searcher.FindOne();

        var user = result.GetDirectoryEntry();

        user.Invoke("ChangePassword", new object[] { oldPassword.Trim(), newPassword.Trim() });
        user.CommitChanges();

        return true;
    }
    */

    using (PrincipalContext ctx = new PrincipalContext(ContextType.Domain, "LDAPIP", userName, password))
    {
        using (UserPrincipal user = UserPrincipal.FindByIdentity(ctx, IdentityType.SamAccountName, userNameI))
        {
            if (user != null)
            {
                user.ChangePassword(oldPassword, newPassword);
                user.Save();

                return true;
            }
            else
            {
                throw new Exception(string.Format("Username not found: {0}", userNameI));
            }
        }

        return false;
    }
}

排查方向

  • 密码历史限制:新密码可能和用户最近使用过的密码重复,AD默认会记录5-10次历史密码,哪怕复杂度达标也会被拦截。可通过AD用户属性查看「密码历史」,或使用域管理员权限强制重置(跳过历史检查)。
  • 密码最短使用期限:部分域策略会设置密码必须使用满指定时长才能修改,若用户刚更改过密码,未到允许修改的时间窗口,会触发该错误。可在组策略「计算机配置→Windows设置→安全设置→账户策略→密码策略」中检查此项。
  • 权限与方法选择:普通用户改自己密码必须遵守所有域策略;若用管理员账号重置,建议用SetPassword替代ChangePassword——前者无需旧密码,且能绕过部分策略限制。
  • LDAP上下文配置:PrincipalContext传入的域地址优先用域名(如contoso.com)而非IP,否则可能无法正确读取域内的密码策略规则。
  • 密码格式隐藏问题:检查新密码是否包含不可见字符(如空格、制表符),或字符串编码异常导致实际发送给AD的密码不符合要求,可在代码中对newPassword做Trim后再传入,或输出日志确认密码内容。

代码调整示例

如果是管理员权限重置密码,修改为以下代码:

using (PrincipalContext ctx = new PrincipalContext(ContextType.Domain, "YOUR_DOMAIN", AD_ADMIN_USER, AD_ADMIN_PWD))
{
    using (UserPrincipal user = UserPrincipal.FindByIdentity(ctx, IdentityType.SamAccountName, userNameI))
    {
        if (user != null)
        {
            // 管理员重置密码,无需旧密码,可绕过部分策略
            user.SetPassword(newPassword);
            user.Save();
            return true;
        }
        else
        {
            throw new Exception($"Username not found: {userNameI}");
        }
    }
}

内容的提问来源于stack exchange,提问作者Abdulaziz Burghal

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.14 23:26:06