Remote users and AD authentication: Required password change is mi

Remote users and AD authentication: Required password change is mi

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Remote users and AD authentication: Required password change is mi Greg @ TPI 08-19-2005
Posted by =?Utf-8?B?R3JlZyBAIFRQSQ==?= on August 19, 2005, 9:38 am
If you were  Registered and logged in, you could reply and use other advanced thread options
We have many users who complain specifically about this issue. They're on the
road when the time comes for them to change their Windows password. Because
they're not on-site they do not receive the prompt at login to change their
password. As such, the next time they log in (let's say a day or two later)
they enter their old password incorrectly and get locked-out. They call us,
we reset their password at the server, and life goes on.

Is there a way to fix this situation? Somehow these remote users are missing
the prompt from AD to make the passwrod change when they try to log in
remotely. Is it a setting or something we missed? Or is this just the nature
of remote users? What do you guys do for this in your domain?

Thanks.

Posted by Steven L Umbach on August 19, 2005, 2:10 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
If they are using the built in Windows VPN client then they should be
getting a prompt to change their password assuming mschap or mscahpv2 are
used for user authentication. If you are using a third party VPN client you
may want to contact the vendor for advice. I have heard that some places
make a hardened computer available via Remote Desktop logon [port 3389 TCP
open in the firewall to it] for remote users for the purpose of logging onto
to change their password. I have never tried that myself to see how well it
works. --- Steve


> We have many users who complain specifically about this issue. They're on
> the
> road when the time comes for them to change their Windows password.
> Because
> they're not on-site they do not receive the prompt at login to change
> their
> password. As such, the next time they log in (let's say a day or two
> later)
> they enter their old password incorrectly and get locked-out. They call
> us,
> we reset their password at the server, and life goes on.
>
> Is there a way to fix this situation? Somehow these remote users are
> missing
> the prompt from AD to make the passwrod change when they try to log in
> remotely. Is it a setting or something we missed? Or is this just the
> nature
> of remote users? What do you guys do for this in your domain?
>
> Thanks.



Similar ThreadsPosted
Password Expiration for Remote Users March 16, 2006, 1:07 pm
Password Policy for remote users May 23, 2006, 3:18 pm
Remote users and Password expiration October 10, 2006, 11:30 am
Can a password be required to print? March 21, 2006, 1:41 pm
No password expiration alert when smart card logon is required December 27, 2005, 1:14 pm
Password Policy forces to change password - but too late... June 27, 2007, 6:32 am
two-factor authentication for both local and remote login July 7, 2006, 6:12 am
Allow users to change Description attribute for computer account July 11, 2005, 5:15 pm
change client password November 3, 2006, 5:26 pm
change service password December 13, 2006, 3:17 am

The site map in XML format XML site map

Contact Us | Privacy Policy