Managing Local Accounts in SMB Mode

To manage local accounts in SMB management mode with a Windows 2016 server, add the local user accounts or the security group that contains the local users to the following policy setting:

Network access: Restrict clients allowed to make remote calls to SAM.

The above policy setting is located under Computer Configuration > Windows Settings > Security Settings > Local Policies > Security Options > Network access: Restrict clients allowed to make remote calls to SAM.

img

When managing local accounts in SMB mode and if the password complexity profile has a maximum password length of greater than or equal to 64 characters, then password rotation may fail.