We are going to roll out 100 remote users running Windows XP - we want these machines in our corporate AD tree so they get GPO's populated to them..these individuals connect to corporate via Netscaler SSLVPN. Questions is this - assuming the user forget his/her workstation domain password - if we reset it from corporate, the changes won't get to them because they are not on VPN (they can't login to launch VPN) - what do companies do in this scenario? We also have Cisco VPN client as an option...thoughts/ideas appreciated.