Knowledge Base

Our dedicated Product Specialist team is always ready to help you when you need it the most. Contact Support

Specops Password Reset

“Access denied” message when enrolling with an admin account

Admin accounts are affected by the adminSDHolder rule, which resets the security permissions on privileged AD accounts every 15 minutes. Possible solution Log in with an account with Domain Admin permissions and run the following command. dsacls "CN=AdminSDHolder, CN=System, <Domain DN>" /G "<ServiceAccount>:CCDC;classStore;" "<ServiceAccount>:LC;;" "<ServiceAccount>:CA;Reset Password;" "<ServiceAccount>:RP;userAccountControl;" "<ServiceAccount>:RPWP;mobile;" "<ServiceAccount>:RPWP;pwdLastSet;" "<ServiceAccount>:RPWP;lockoutTime;" Example: dsacls "CN=AdminSDHolder, CN=System, DC=example,...

When the user follows the enrollment reminder link, they are told that they do not have a configured enrollment policy

The service account has lost permissions to read the Specops Password Reset Group Policy Object. Possible solution From the Group Policy Management Console, add the service account to the Delegation Tab of the Specops Password Reset Group Policy Object with Read rights.

LDAP Bind error on Helpdesk Password Reset

When using Specops Password Reset with Delegated Helpdesk enabled, helpdesk users may encounter the following error when attempting to reset a user’s password in Microsoft Edge or Google Chrome browsers: Password reset failed: OperationsError (000004DC: LdapErr: DSID-0C090F6A, comment: In order to perform this operation a successful bind must be completed on the connection., data 0,...

Failed to get the SPR service account UPN from the server ‘..’ Identity check failed for outgoing message. The expected DNS identity of the remote endpoint was ..

The following error message was received after a Specops Password Reset installation or upgrade: Failed to get the SPR service account UPN from the server ‘..’Identity check failed for outgoing message. The expected DNS identity of the remote endpoint was ‘..’ but the remote endpoint provided DNS claim ‘..’. If this is a legitimate remote...

403 – Forbidden: Access is denied when browsing to your Specops Password Reset site.

Description: When you browse out to your Specops Password Reset site you encounter the following error: 403 – Forbidden: Access is denied. You do not have permission to view this directory or page using the credentials that you supplied. Solution: Generally if you see this message, it can be one of the two items below....

User receives “the certificate revocation list server could not be reached” message when they click the reset password link at the logon screen, but not when they browse to the reset page when logged in.

User is not connected to the internet at the logon screen. Possible solution You can use one of the following three options below to solve this issue: Add a new rule to your proxy that allows “domain computers” to reach the CRL servers on the internet. The rule will look similar to the example below:...

How to install a webserver on a domain joined machine on a DMZ via the command line

Here is the code below: Here is an example:

Service failed to start (Initializing ServiceHost) System.InvalidOperationException: Cannot find the X.509 certificate using the following…

The Specops Password Reset Server Service will not start on the server, the application log is showing the following error: Service failed to start (Initializing ServiceHost)System.InvalidOperationException: Cannot find the X.509 certificate using the following search criteria: StoreName ‘My’, StoreLocation ‘LocalMachine’, FindType ‘FindByThumbprint’, FindValue ‘..’.at System.ServiceModel.Security.SecurityUtils.GetCertificateFromStoreCore(StoreName storeName, StoreLocation storeLocation, X509FindType findType, Object findValue, EndpointAddress target, Boolean...

Errors after disabling TLS 1.0 and TLS 1.1 with Specops Password Reset

Description: In some instances, customers who have disabled TLS versions 1.0 and TLS 1.1 may see errors when users try to use Specops Password Reset by browsing to the password reset page. Users might see this error when browsing to the Password Reset site: “An unknown error has occurred” When you check the Application logs...

Updating the Specops Password Reset Server Certificate

Specops Password Reset Server service uses a self-signed certificate to encrypt communications from the Password Reset Web (IIS) components. If this certificate is expired or inadvertently deleted, the Password Reset server may not be able to start. Identify the Certificate Currently In Use In order to check the certificate currently in use today, open the...
« Previous PageNext Page »