We discovered that although through normal conventions, a user is unable to use their last 12 passwords in active directory, when resetting with the ADSelfService page, they are able to use the current or last 12 password to successfully reset their password.
Is there anyway to prevent this?
Has anyone else experienced this?
Thanks