A password reset worked in the cloud but not on the local network

The reset was made as a cloud-only change. Where a client's accounts live in their own directory, the reset has to go there instead.

The person can sign in to email and cannot sign in to their computer. Their new password works in one place and not the other.

The split happens when the reset changed the cloud account, while the account they log in to their machine with lives in the client’s own directory.

Avvi guards against this where it can see an on-premises connector, and refuses rather than doing half the job. The symptom appears when it could not see one.

Symptom

The new password works for Microsoft 365 and is rejected on the domain-joined machine.

Or the person can log in to their machine with the old password, which still works.

Cause

Where a client runs their own directory, that is where the account lives and where the password has to change.

Avvi routes a reset there automatically when it can see a connector with the Identity module checking in. In that case both places end up consistent.

If no such connector is enrolled for the client, the reset is a cloud change only, and the local password is untouched.

If a connector exists but was not reachable, Avvi refuses the reset outright rather than making a cloud-only change it cannot verify. That produces a clear message rather than this symptom.

The remaining case is an account explicitly treated as cloud-only when it was not.

Fix

  1. Check whether the client has a connector with the Identity module, and whether it is reachable.
  2. If there is no connector, the local password has to be changed on the client’s own directory. Avvi cannot reach it.
  3. If the connector is there but not reachable, bring it back and ask for the reset again. Avvi will route it correctly.
  4. If the connector is healthy, ask Avvi to reset the password again without treating the account as cloud-only.

Once routed correctly, the local and cloud passwords should end up consistent without a second request. Check both rather than assuming.

If something doesn’t look right

If Avvi refuses the reset and names the connector, that refusal is doing its job. Bring the machine back rather than working around it.

If the person needs access to their machine today and the connector cannot be brought back quickly, that reset has to happen on the client’s directory directly.

If the local password changes and the cloud one does not follow, that is a directory synchronisation question on the client’s side rather than something Avvi controls.

To report it, open a support conversation from the Help drawer with the client, the person, and whether a connector with the Identity module is enrolled.

FAQ

Q: Can Avvi reset the local password without a connector?

A: No. Reaching a client’s own directory is what the connector is for.

Q: Why did Avvi refuse instead of resetting the cloud password?

A: Because it could not confirm the account was cloud-only, and a half-done reset is worse than none.

Q: Can I ask for a temporary password on these accounts?

A: No. Where the account lives in the client’s own directory, only a permanent password is supported.

We value your privacy

We use cookies to improve your experience, analyse traffic and measure our marketing. You can choose what to allow. Cookie Policy