Problem:
After checking in a Centrify Privileged Service (CPS) managed account password, the account shows the status of "failed". The account is no longer usable.
Cause:
In CPS, when a user checks in a password, CPS will try to rotate (change) the password. It may fail because the Minimum Password Age is set to a value greater than 0 days. For example, if the minimum password age is set in Active Directory to be 4 days, then when CPS retries to change the password before the 4 days is up, it fails. CPS will retry several times and eventually the account gets locked out. Once the account is locked, CPS will fail to login to the account or change the password even after 4 days.
Work-around:
Set the minimum password age group policy for managed accounts to 0 days.
Resolution:
This issue will be addressed in a future release of Centrify Privileged Service.