Tips for finding Knowledge Articles

  • - Enter just a few key words related to your question or problem
  • - Add Key words to refine your search as necessary
  • - Do not use punctuation
  • - Search is not case sensitive
  • - Avoid non-descriptive filler words like "how", "the", "what", etc.
  • - If you do not find what you are looking for the first time,reduce the number of key words you enter and try searching again.
  • - Minimum supported Internet Explorer version is IE9
Home  >

KB-8758: Centrify Privileged Service Managed Account Show the Status "Failed" in the Tenant

Privileged Access Service ,  

24 May,17 at 05:03 PM


After checking in a Centrify Privileged Service (CPS) managed account password, the account shows the status of "failed".  The account is no longer usable. 
User-added image

In CPS, when a user checks in a password, CPS will try to rotate (change) the password. It may fail because the Minimum Password Age is set to a value greater than 0 days. For example, if the minimum password age is set in Active Directory to be 4 days, then when CPS retries to change the password before the 4 days is up, it fails.  CPS will retry several times and eventually the account gets locked out. Once the account is locked, CPS will fail to login to the account or change the password even after 4 days. 

Set the minimum password age group policy for managed accounts to 0 days.

This issue will be addressed in a future release of Centrify Privileged Service.