Remote computer

  • Thread starter Thread starter Invisible
  • Start date Start date
I

Invisible

This one should be fairly simple...

Let me try to explain this in few words. I'm setting up a laptop for a
guy working from home. He's going to use a VPN to connect in to part of
our network and access some terminal servers.

Long story short: At the moment of login, no DCs are reachable. (He
hasn't even dialled the Internet yet, never mind authenticated into the
VPN!)

That's fine - the laptop will use the cached password for the domain
account. But... what happens when the user needs to CHANGE the password?

Of course, if you're on a terminal server, it's quite easy to change
your password. And then our DC will use the new password. But how the
hell will the laptop know about this? (This is compounded by the fact
that our DC isn't actually accessible over the VPN. Apparently that
would require additional hardware or something...)

I could just make the password never expire - but I'd really prefer not
to if there's a way.

Any suggestions?
 
If your DC is not available over the VPN then you have not choice but to set
his password to never expires as access to a domain controller is mandatory
to change a password. In a normal scenario where a user access a VPN that
connects to the domain the user should be prompted to change his password
when it expires assuming that the VPN client can accommodate that which the
built in MS VPN client can also long as MSCHAPV2 is selected and Remote
Access Policies allows remote password changed. Then their is the problem
with the cached credentials after a domain password changed. To deal with
that a user should immediately lock their computer after changing their
domain password and unlock it using the new password. --- Steve
 
If your DC is not available over the VPN then you have not choice but to set
his password to never expires as access to a domain controller is mandatory
to change a password.

OK. Well I'll see if I can get that altered. (It just ocurred to me that
we created a backup DC at the other site. If we could make THAT
available over the VPN then part of the problem is solved.)
In a normal scenario where a user access a VPN that
connects to the domain the user should be prompted to change his password
when it expires assuming that the VPN client can accommodate that

I'm using a Cisco VPN client. I'll have to check out the documentation -
I think there are some settings relating to that.
Then their is the problem
with the cached credentials after a domain password changed. To deal with
that a user should immediately lock their computer after changing their
domain password and unlock it using the new password. --- Steve

OK, thanks for that.
 
Back
Top