Managing Local Accounts in SMB Mode
To manage local accounts in SMB management mode with a Windows 2016 server, add the local user accounts or the security group that contains the local users to the following policy setting:
Network access: Restrict clients allowed to make remote calls to SAM.
The above policy setting is located under Computer Configuration > Windows Settings > Security Settings > Local Policies > Security Options > Network access: Restrict clients allowed to make remote calls to SAM.
When managing local accounts in SMB mode and if the password complexity profile has a maximum password length of greater than or equal to 64 characters, then password rotation may fail.