Avatar of Leadtheway
Leadtheway
Flag for United States of America asked on

Remote users password Sync

Currently have several users working remotely due to Covid, we have some users using RDS gateways with Duo and some using VPN with duo. Issue we seem to be having is if a user password expires they can't either use the VPN or if using the RDS gateway, the machine they are using to initiate can't be logged into after password expires .  They would have to use old password to log in and then the password gets changed when either rds session initiates or they are able to access our self service password reset.  How does everyone handle remove users and making sure passwords get synced?
Remote AccessActive DirectoryVPN

Avatar of undefined
Last Comment
Leadtheway

8/22/2022 - Mon
Pete Long

Do you have Exchange (OWA), or ADFS?

P
arnold

The local system cache will be using the old password, unless they establish the VPN before login into the system at which point the password should synchronize.

The VPN, RDS will use the new credentials. Potentially you have a way to update the password.
Leadtheway

ASKER
we have hybrid O365
All of life is about relationships, and EE has made a viirtual community a real community. It lifts everyone's boat
William Peck
Leadtheway

ASKER
@arnold  yeah thats the problem is the local system cache.  So theres nothing really to be done?
ASKER CERTIFIED SOLUTION
arnold

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.
Leadtheway

ASKER
yeah we are using cisco anyconnect, so I will dig into that and see..probably going to be the only viable solution. Thanks
Pete Long

Why not get AnyConnect to prompt when the password is about to expire and ask the user to change it?



⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
Leadtheway

ASKER
we have Manage engine that does it as well, gives them pop ups and sends emails starting 7 days out.  Could anyconnect prompt them when logging in?  i think still doing the SBL option is going to be the most user transparent