Re: Changing passwords for remote users

From: Adam Arndt (a-adama_at_microsoft.com)
Date: 04/28/04


Date: Wed, 28 Apr 2004 15:41:30 -0400

This is a very common problem that I see all of the time. It is usually
caused by a 3rd party vpn client (most notably, Cisco) that does not
properly update the client's cached password when it is changed in the VPN
connection. The most common workaround for this issue is to educate users
that if they are remotely connected and they change their password (whether
in a VPN, terminal session, or Outlook/ OWA) they need to lock and unlock
their workstation while still in the VPN connection. This will cause the
cached password to be updated. Another solution, is to (if your VPN client
supports it) require that when remote users logon they logon to their
machines using the "logon using dial-up conneciton" check box (which will
also logon using VPN connection if they are using the Microsoft VPN client.)

Hope it helps,
Adam Arndt

"Fredj" <fredj_74@hotmail.com> wrote in message
news:2bd7dc14.0404280841.58b233a4@posting.google.com...
> Were you able to resolve this issue? If yes, mind pointing me toward the
> fix?
>
> "Phyllis" <anonymous@discussions.microsoft.com> wrote in message
> news:<1b6a401c420b5$47f56350$a501280a@phx.gbl>...
>> My office has recently implemented a policy of requiring
>> regular password changes. This is fine for our staff
>> that are regularly in the office and are notified before
>> the password expires. This is a problem for our remote
>> users. They are not notified until they connect via VPN
>> and are forced to change their password at that point.
>> Our users are standardized on Windows 2000. The problem
>> then is that the locally cached password is different.
>> They must login to their machine with their old
>> password. Also each time they access a network resource,
>> such as the mail server when opening outlook, they are
>> promted for username password and domain. We have been
>> working around this until the three days that our policy
>> requires has passed and the user can VPN and manually
>> perform another password change which gets them back in
>> sync. I am sure that my organization is not the only
>> organization with such a security policy and a large
>> number of remote users. I would just like to know what
>> the proper way is to deal with these password changes. If
>> there is an easier way to deal with these password
>> changes is there is some configuration change that needs
>> to be made either on the network or on these individuals
>> machines.



Relevant Pages

  • RE: SBS Standard VPN Setup using L2TP
    ... I understand that the login script is not applied when users logon through ... Windows" dialog box and choose an appropriate connection to gain access to ... and then logon by using dial-up connection option after you create the VPN ... Did you configure a login script group policy in AD or configure a logon ...
    (microsoft.public.windows.server.sbs)
  • Re: Strange VPN problem
    ... What IOS version TAC suggests to get rid off this problem? ... >> When I'm connected to my VPN gateway with Cisco VPN ... This issue occurs whether the vpn connection is idle or there is ... That's why I reinstalled the VPN client, ...
    (comp.dcom.sys.cisco)
  • Re: Enable Remote Laptops to run GPOs, and access files
    ... I can think of at least two ways that you could do this using a VPN connection. ... and scripts over the Internet without any need to use a VPN client. ... Then create an IPSec policy that forces ...
    (microsoft.public.windows.server.networking)
  • RE: PPTP VPN connection problems
    ... Since you want to contact your local MS support for help, ... Additional, you can establish the VPN connection from internal client, that ... | A ping to the server would result in "Request timed out". ...
    (microsoft.public.windows.server.sbs)
  • RE: PPTP VPN connection problems
    ... But I do not think it is in the ADSL router itself. ... They do not say it but maybe they prohibit VPN connections ... fix IP for my connection – PPPoE/PPPoA) subscription at belgacom in Belgium ... | A ping to the server would result in "Request timed out". ...
    (microsoft.public.windows.server.sbs)