RSAT - Access denied - After August KB5016616 & kb5012170 updates

Blast 16 Reputation points
2022-08-19T09:22:46.61+00:00

Hello,

after installing the latest cumulative(KB5016616) and security(KB5012170) updates for August for win10 ver. 20H2 1094.1889, our HelpDesk is having problems with RSAT.
While traying to reset password they obtain following error "Windows cannot complete the password change for user because: Access is denied".

They have delegated rights for specific OU with security group to reset password, and they are not members of any admin builtin groups because we don't want them to have administrator rights.

After uninstalling of the latest patches the error is gone and they again can reset password.

Has anyone run into the same problem?

Also did anyone found maybe any workaround or fix for this issue?

Also our DC is on 2012 R2 and worksations are on Win 10 20H2.

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,170 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,898 questions
Windows Server Management
Windows Server Management
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Management: The act or process of organizing, handling, directing or controlling something.
421 questions
Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,758 questions
{count} votes

8 answers

Sort by: Most helpful
  1. Scuzzy5150 1 Reputation point
    2022-10-19T13:44:02.107+00:00

    An important question for all experiencing this issue:

    How many of you have the following GPO setting for your domain controllers defined: Computer Configuration\Policies\Windows Settings\Security Settings\Local Settings\Security Options--> Network Access: Restrict Clients Allowed to Make Remote Calls to SAM Enabled, Security Descriptor = O:BAG:BAD:(A;;RC;;;BA)(A;;RC;;;

    Though some of you may have compliance/regulatory concerns by changing this, if you add the AD group that needs the Reset Passwords permission, those users should be able to reset passwords again. If some of you are unable/unwilling to do this, I've found that resetting passwords via the Active Directory Administrative Center is a viable workaround.


  2. q sligh 21 Reputation points
    2022-11-08T19:03:19.337+00:00

    I've encountered the same issue on Win11, but if I log onto one of our virtuals, I have no issues, no matter the OS version.

    0 comments No comments

  3. Nick Karamath 1 Reputation point
    2022-11-25T10:55:58.797+00:00

    Hi guys

    Having the same issue but it is on windows server 2019 RSAT feature.

    Would it be a similar August update to affect this issue?

    This has just come out of nowhere also and affected our service desk.