My Service Support

How to Change a Password in Active Directory

Updated 2026-08-17 · 971 words

Be the first to rate this page

Change Your Active Directory Password

If you are signed in to a Windows computer with your domain account and still know your current password, you can usually change it from the standard Windows security screen.

  1. Connect the computer to your organization’s network. If you are away from the workplace, connect through an approved remote-access method if your organization requires it.
  2. Open the Windows security screen by pressing Ctrl, Alt, and Delete together.
  3. Select the option for changing a password.
  4. Enter your current password, then enter and confirm the new password.
  5. Submit the change and wait for Windows to confirm whether it was accepted.

This is the usual active directory change password process for a signed-in user. Your organization may enforce rules for password length, complexity, reuse, or prohibited words. Follow any message shown on the screen rather than repeatedly trying the same rejected password.

If you use a remote Windows session, the key combination may affect your local device instead. Use the remote session’s approved command or security control to open its Windows security screen.

Reset a User Password as an Administrator

An administrator may be able to reset a user’s password in Active Directory Users and Computers. Availability depends on the organization’s delegated permissions, tools, and security procedures.

  1. Open Active Directory Users and Computers from an authorized administrative workstation.
  2. Find the correct domain, organizational unit, and user account.
  3. Confirm the user’s identity and the exact account before making a change.
  4. Open the account’s available password action and enter a temporary or replacement password that meets the organization’s policy.
  5. Apply any required sign-in setting, such as requiring the user to choose a new password at the next eligible sign-in.
  6. Tell the user how the new credential will be delivered through an approved channel.

Interface wording and available choices can vary. Do not assume that access to the directory automatically includes authority to reset every account. If the action is unavailable, follow the organization’s escalation process.

Password Reset vs. Password Change

An Active Directory password change is normally started by the account owner. The user knows the current password and proves that knowledge by entering it before choosing a new one.

A password reset is normally started by an authorized administrator or an approved self-service system. It is used when the current password is forgotten, expired in a way that prevents normal access, or otherwise unavailable. A reset generally does not require the old password, but identity verification may be required.

This is the main distinction in active directory reset password vs change password questions: a change continues from a known credential, while a reset replaces a credential the user cannot use. Reset vs change password Active Directory behavior can also differ for saved credentials, encrypted data, certificates, and access tokens. An administrator should follow local policy because a reset can have effects beyond ordinary sign-in.

Change a Password from a Remote or Mobile Device

Remote options depend on what the organization has approved and configured. An active directory password change app may be a self-service password tool, a company access app, or a remote desktop service. Some organizations instead require a managed computer connected through their VPN or another secure remote-access system.

  • Use only the organization’s approved app or access method.
  • Complete any required identity verification.
  • Keep the device connected to the organization’s network while submitting the new password.
  • Read the confirmation carefully before closing the app or disconnecting.

A mobile device may let you submit a change or reset without updating the cached Windows sign-in on a separate computer. If that computer is offline, connect it to the organization’s network using the method provided by IT. Do not use unapproved tools or attempt to work around access controls.

If the New Password Does Not Work

First, check the exact error. A password-policy message can mean the new password is too short, lacks required character types, resembles account information, or was used recently. Choose a different password that follows the displayed requirements.

If the account is locked, more attempts may prolong the problem under some policies. Stop retrying and contact the organization’s IT administrator or help desk through an approved channel.

Domain connectivity also matters. A computer that cannot reach the organization’s network may continue accepting cached credentials for Windows sign-in while online services expect the new password. This can make both passwords appear inconsistent. Connect through the approved network or remote-access service and try again.

Changes may also take time to reach every domain system because directory servers replicate updates. Avoid switching repeatedly between the old and new passwords, which can trigger lockouts when apps continue submitting saved credentials.

Contact IT if neither password works, the account status is unclear, the change produced an encryption or certificate warning, or you cannot establish domain connectivity. Provide the error text, device type, whether you are on-site or remote, and which sign-in failed. Never send the password itself.

After Changing or Resetting the Password

After you change password in Active Directory, update places that may still store the old credential. Otherwise, background sign-in attempts can lock the account.

  • Lock and unlock the Windows session with the new password while connected to the organization’s network.
  • Update saved credentials in approved VPN or remote-access connections.
  • Respond to password prompts in desktop and mobile email clients.
  • Reconnect mapped drives or shared folders that request the old credential.
  • Update managed phones, tablets, and work apps that use the domain account.
  • Review scheduled tasks or approved services that run under the affected account, if this is part of your role.

Sign out of sessions that continue to fail, then sign in again with the new password. If you do not know how to change Active Directory password details on a managed device, or a saved credential cannot be updated, ask your IT administrator for the organization’s approved procedure.

Was this page helpful?

Be the first to rate this page