Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Filevault - expertise needed

We have a user that recently changed AD password on the mac and it worked fine. 4 days after user restart the MAC, and filevault is asking for password, and will not accept anything. Not new or old password


We have tried to recover password by using the "forgot password" option in recovery. The user enter the apple id and login and then can type a new password - but then the error comes


Reset password failed


Authentication server refused operation because the current credentials are not authorized for the requested operation


The user only have used this apple Id on the computer, so it must be the valid one.


What can be done to get this reset ?

Posted on Mar 1, 2018 11:47 PM

Reply

Similar questions

18 replies

Mar 2, 2018 8:24 AM in response to dvbguy

Did you checked the box of my password doesn't work when logging in and click on next and see what are the upcoming steps .

And also firmware password should not be enabled in your Mac ( in case if is used it should be disabled ) also when Apple ID is signed in , the latest changes are it will ask for security questions and answers on appleid.apple.com correct answers are to be filled up then the user can login .

User uploaded file

Mar 2, 2018 6:32 AM in response to dvbguy

See this article Change or reset the password of a macOS user account - Apple Support

You must follow the paragraph -

Reset using the Reset Password assistant (FileVault must be on)

if it doesn't work multiple method are there to reset password .

Also sometimes login keychain is deleted from keychain access , the last paragraph is giving the method to create new login keychain . And do you use iCloud Keychain .

Mar 2, 2018 8:03 AM in response to tygb

Yes - it is the password assistant we try


Choosing "I forgot my password" - entering the apple ID of the user -- and afterwards It ask for a new password - and then the error comes


Reset password failed


Authentication server refused operation because the current credentials are not authorized for the requested operation

Mar 2, 2018 9:51 AM in response to tygb

The user know the login password for the computer of course- but for some reason the filevault at login will not accept it. It happened after password was changed. And the next restart the user was not able to login


Does it make sense to go to a apple if the filevault key is not available

Mar 2, 2018 1:21 PM in response to dvbguy

That’s unfortunate. If another user doesn’t exist on the MacBook then the only way to get around FileVault is to erase your startup disk and lose all of your data.


That being said, if the MacBook is AD bound and the user changed their password for AD, I’d assume that the data is actually stored on the AD server and the MacBook merely displays it on the desktop so that it can be viewed, edited or deleted remotely. The system itself is certainly encrypted, but I doubt if any personal files are really on there.


Does more than one user show up at the FileVault login window (other than the guest account)? If so, are any of these other users administrators?

Mar 3, 2018 1:08 AM in response to Encryptor5000

Because the Mac is AD joined, the data is still saved on the desktop


There is only one user when starting up, but there is also a admin user, but is not listed at the startup


I cannot understand why in the password assistant the user enter the apple id and a password reset is possible, but then it just say


Reset password failed


Authentication server refused operation because the current credentials are not authorized for the requested operation


If I try with a different apple id, I don´t even get the option to reset the password, so the apple id looks correct, but the reset then fails for some reason?

Mar 3, 2018 6:27 AM in response to dvbguy

I’m surprised that Password Reset Assistant refuses to let you reset your password even though you have the correct Apple ID. Maybe your AD administrator has to reset the password for you in order for it to be accepted.


Regardless, does FileVault offer an “Other” button that allows you to log in as the administrator? Or are you only able to log in as the one user?


If you’re only able to log in as the one user, unfortunately your only option now is to erase your Mac and to reinstall macOS in order to get around FileVault.


If you are able to log in as the administrator at the FileVault login screen, you can resync the user’s password with FileVault by disabling FileVault, then turning it back on again.

Filevault - expertise needed

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.