| Previous | Next |
| EAS_E_REQUESTED_POLICY_PASSWORD_EXPIRATION_INCOMPATIBLE | EAS_E_ADMINS_HAVE_BLANK_PASSWORD |
EAS_E_USER_CANNOT_CHANGE_PASSWORD
EAS_E_USER_CANNOT_CHANGE_PASSWORD means that the current user is subject to EAS password requirements but account policy or account state prevents that user from changing the password.
The contract behind the HRESULT
A blank password and an inability to change a password are distinct blockers and may require different administrators.
Diagnostic worksheet
- Account type, User cannot change password flag, ACL/policy source, and control-user role
- Required EAS password action and current compliance result
- Domain/provider authority for connected accounts
- Administrator and recovery path that can safely change the restriction
Reproduce the condition safely
- Test a disposable account with and without the restriction.
- Attempt the normal password-change UI rather than direct credential manipulation.
- Re-evaluate after authorized policy correction.
Nearby states and false leads
Read the comparison results in this order for current-user password-change restriction:
Closing the incident
Apply the smallest change that addresses the first rejected condition: Remove the unintended restriction through the owning account authority or adjust the EAS requirement if the account is outside local control.
Close the incident only when the user can complete a normal password change, retain recovery access, and the device becomes compliant.
Technical references
Looking for a different code? Search another status or error code.