| Previous | Next |
| EAS_E_USER_CANNOT_CHANGE_PASSWORD | EAS_E_ADMINS_CANNOT_CHANGE_PASSWORD |
EAS_E_ADMINS_HAVE_BLANK_PASSWORD
EAS_E_ADMINS_HAVE_BLANK_PASSWORD means that one or more enabled local administrator accounts have blank passwords, preventing device-wide EAS password compliance.
Meaning in the subsystem
EAS compliance is a policy merge, not a single password test. Windows evaluates the requested settings against local accounts, connected accounts, domain or management policy, and operating-system capabilities; the individual fields in EasComplianceResults show which requirement changed the decision.
Fixing only the currently signed-in user is insufficient because EAS evaluates administrator accounts device-wide.
Minimum useful evidence
- Complete enabled local Administrators membership, including renamed/built-in accounts
- Password-required/disabled state for each administrator without exposing secrets
- Policy scope showing why administrators are always evaluated
- CheckCompliance result and affected account count
Isolate the responsible condition
- Disable an unused test administrator or assign a compliant password, then re-evaluate.
- Compare standard control-user compliance with administrator compliance.
- Verify service accounts are not accidentally placed in Administrators.
Regression proof
Apply the smallest change that addresses the first rejected condition: Secure, disable, or remove unintended administrator accounts through an auditable account-management process.
Close the incident only when every enabled administrator has a compliant recoverable credential and newly created administrators are covered by policy tests.
Technical references
Looking for a different code? Search another status or error code.
