      I'm getting the feeling that I'm missing something simple here, but here it goes anyway: after an user uses the auto recovery method to change PBE password, the domain password is not synced back. I made sure that the "Synchronize Endpoint Encryption password with Windows" was enabled on the applied policy and SSO worked fine before the auto recovery. The behavior I was expecting is: user changes the password through auto recovery > User logs on to Windows > PBE password is synced back > next time user reboots, Windows password should be entered. But what I get is: user changes PBE password though auto recovery > user logs on to Windows > user reboots and has to use the new PBE password to get through and then enter user password again. What gives?