| Previous | Next |
| ERROR_PWD_TOO_RECENT | ERROR_UNSUPPORTED_COMPRESSION |
ERROR_PWD_HISTORY_CONFLICT
What ERROR_PWD_HISTORY_CONFLICT means
Windows password-history policy keeps hashes of a configured number of previous passwords. A new value that matches one of those entries is rejected even when it satisfies length and complexity requirements.
Where it commonly appears
- Interactive password changes
- Help-desk resets subject to domain policy
- Automated service-account rotation
- Provisioning systems that reuse a fixed credential pool
Likely causes
- The new password was used recently
- Automation rotates among too few predefined values
- The effective history length is larger than the application assumes
- A reset workflow attempts to restore the old password after a partial failure
Troubleshooting checklist
- Check the effective password-history policy for the account
- Review rotation logic for deterministic reuse
- Confirm whether fine-grained policy differs from the domain default
- Never log or compare plaintext passwords during troubleshooting
Guidance for developers
Generate genuinely new credentials and design rotation as a transaction so a failed downstream update does not require reverting to a history-prohibited value. Treat the domain controller as authoritative.
Guidance for administrators
Correct rotation tooling rather than reducing history depth without security review. For emergency recovery, follow the organization’s privileged account procedure.
Example
A deployment tool alternates between two service-account passwords. With a history depth of 24, the third rotation tries to reuse the first value and receives this code. Randomly generated unique credentials remove the conflict.
Related conditions
Password complexity and minimum length can pass while history still fails. ERROR_PWD_TOO_RECENT is about when the change occurs, not which value is chosen.
References
Looking for a different code? Search another status or error code.