Controls whether the user must change the password the next time the user logs on.
| Attribute property | Value | Description |
|---|---|---|
| adminDisplayName | Pwd-Last-Set | Display name of this object for use in directory service administrative tools. |
| adminDescription | Pwd-Last-Set | Description of this object for use in directory service administrative tools. |
| cn | Pwd-Last-Set | Common name. |
| lDAPDisplayName | pwdLastSet | The name used by LDAP clients to refer to the object's class. |
| attributeID | 1.2.840.113556.1.4.96 | A unique OID that identifies the attribute. |
| objectClass | Attribute-Schema | The class of which this object is an instance. |
| objectCategory | Attribute-Schema | Reference to an object class or one of its superclasses, which is used when searching for this object. |
| schemaIDGUID | {BF967A0A-0DE6-11D0-A285-00AA003049E2} | A GUID that uniquely identifies this object. You can use this string value in an ACE to control access to objects of this object. |
| attributeSyntax | 2.5.5.16 | An OID of a syntax. The combination of the attributeSyntax and oMSyntax properties determines the syntax of an attribute. |
| oMSyntax | 65 | Syntax of this attribute as defined by the XAPIA XOM (X/Open Object Model) specification. |
| isSingleValued | TRUE | TRUE means that the attribute has a single value, FALSE means that the attribute can have multiple values. |
| attributeSecurityGUID | {4C164200-20C0-11D0-A768-00AA006E0529} | An optional GUID that identifies the attribute as a member of an attribute set(also known as a property set). |
| showInAdvancedViewOnly | TRUE | TRUE means that the object will apear in the Advanced View of the Users and Computers snap-in only, but not in the Windows shell. FALSE means that the object will appear in Normal view of the Users and Computers snap-in and the Windows shell. |
| systemFlags | 16 | An integer value that contains flags that define additional properties of this object. Category 1 classes or attributes have the 0x10 bit set by the system and cannot be set by users. They are shipped with Active Directory. For more information, see ADS_SYSETMFLAG_ENUM enumeration in ADSI Reference. |
| systemOnly | FALSE | TRUE means that only Active Directory can modify the class of this object. FALSE means users can make the modification as well. |
| Remarks | Default is 0. The value 0 means the user must change the password at the next logon. The value -1 means the user does not need to change the password at the next logon. The system sets this value to -1 after the user has set the password. |