Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations TouchToneTommy on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

The best way to change remote users passwords?

Status
Not open for further replies.

UKHicks

IS-IT--Management
May 11, 2004
141
US
We have a lot of remote users who we have given laptops. The laptops are joined to the domain, and typically they do not vpn into our network because a lot of the time they use Outlook 2003 with rpc over http, and they keep thier files locally.

The problem is this, every time we have to change thier passwords, or thier password simply expires (every 90 days), we have a hell of a time. They are logging into their domain accounts on the laptop when they are not connected through the vpn, and are using the local cached password. Which is no longer up to date after a password change.

What do you guys commonly do to work around this problem?

Is there a way of clearing the locally cached password on thier laptops?

Thanks!
 
Does the system not hust force them to change the password the next time they connect? The domain account can't be used as the password has expired.
 
Not when the laptop is not connected to the network, it still thinks the password is current
 
I can see it's a pain but the password will only work on the local local pc it no longer has access to your domain.
 
RPC of HTTP is very cool, but your laptop users are using outlook which doesn't allow them to change passwords. Research the possibility of using OWA in your environment. In OWA there is an options area which an options can be cofigured to allow your client to change passwords. It will also warn them when the password is about to expire. Because you access OWA via a web browser it is independent from the credentials in the local users profile. If a users logon has expired your help desk just needs to reset it and then the user can change it.
 
I don't think OWA is going to be a solution for remote users, as your consultants will need to create a either a vpn connection or will need to create a secure http connection.

In my experience client site are unlikely to allow such connections though their firewall.

The only solution I can think of is providing your client with GPRS cards and asking them VPN into the network before they use Outlook.
 
We use PIX 501 Firewalls into our network. They keep a VPN tunnel and authenticate to he domain to force password change (policies). They are not cheap and may not be an answer. Are your remote users local or out of area? We had the same problems, but we moved all remote sites to PIX's and users can go toa remote site or come into the corp. office.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top