From MySQL (DOC 5.7.6 )
MySQL restricts the client to “sandbox mode” in which the server permits to the client only those operations necessary to reset the expired password. Which action is taken by the server depends on both client and server settings, as discussed later.

These operations are permitted If the server restricts the client to sandbox mode

  • The client can reset the account password with ALTER USER or SET PASSWORD. The server restores normal access. Sandbox don’t take effect
  • The client can use SET statements

How to activate the sandbok mode

  • Set disconnect_on_expired_password to disabled.
  • If disconnect_on_expired_password is enabled (is the default), the server disconnects the client with an ER_MUST_CHANGE_PASSWORD_LOGIN error.



