Changing a Domain Password When Paste Fails in PowerShell

While changing a domain administrator’s password in Windows PowerShell on a domain controller, I ran into a paste problem with Read-Host -AsSecureString. Typing a password manually worked, but pasting into the hidden prompt left the variable empty. Reading the clipboard with Get-Clipboard and converting its contents to a SecureString worked in the same session.

This is the procedure I used. It changes the password of the currently signed-in domain account and requires its existing password.

Load the Active Directory module and enter the old password

Run Windows PowerShell on the domain controller while signed in as the domain account whose password you want to change. Check the current identity, then load the module:

whoami
Import-Module ActiveDirectory

If manual entry works, enter the existing password at a hidden prompt:

$oldPassword = Read-Host 'Old password' -AsSecureString

If you already have the correct password in $oldPassword, keep that variable and continue. If pasting the old password also fails, use the clipboard procedure below with $oldPassword instead of $newPassword.

Read the new password from the clipboard

The order matters: copying a PowerShell command replaces whatever password was previously in the clipboard. Prepare the command first, then copy the password.

Paste the following command at the ordinary PowerShell prompt, but do not press Enter yet:

$newPassword = ConvertTo-SecureString -String (Get-Clipboard -Raw) -AsPlainText -Force -ErrorAction Stop

Now copy only the intended new password, without surrounding quotes, extra spaces or a line break. Return to PowerShell and press Enter. The command reads the clipboard directly, so there is no hidden input prompt to paste into.

Get-Clipboard -Raw returns the clipboard text as a single string. ConvertTo-SecureString -AsPlainText -Force converts that text to the type expected by the password-change command. See Microsoft’s documentation for Get-Clipboard and ConvertTo-SecureString.

Check that the password was captured

Check the number of characters without displaying the password itself:

$newPassword.Length

It should match the length of the password you copied. If clipboard reading or conversion reports an error, correct that before running the password change. In my original tests, manually entered text was captured, while the unsuccessful paste attempts produced an empty value.

Change the current domain account’s password

Once both variables contain the intended values, run this single-line command:

Set-ADAccountPassword -Identity $env:USERNAME -OldPassword $oldPassword -NewPassword $newPassword -ErrorAction Stop

$env:USERNAME identifies the current account by its logon name. The command supplies the old and new passwords; it does not use the -Reset switch. A successful invocation normally returns no output. The parameters are documented in Set-ADAccountPassword.

Errors encountered along the way

Before the clipboard workaround succeeded, I saw two different errors. They describe different failures:

The specified network password is not correct

This was error 86. Check the existing password in $oldPassword and the account selected by -Identity.

The password does not meet the length, complexity, or history requirement of the domain.

This was error 1325. The proposed new password was rejected by the domain’s password policy. Capturing the intended password correctly and satisfying the policy are separate requirements.

The clipboard method resolved the paste problem in this session, and the password change completed successfully. It does not establish why the hidden prompt failed to accept pasted input or imply that all PowerShell consoles behave the same way.

Leave a Reply

Your email address will not be published. Required fields are marked *