<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Local User Database :: Password Change :: VPN Global Protect Client in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/local-user-database-password-change-vpn-global-protect-client/m-p/140484#M48281</link>
    <description>&lt;P&gt;I don't believe that this is an option as is.&amp;nbsp;If this isn't already a feature request I would be kind of suprised, add your vote to the request through your SE or have him put a request in for it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This could potentially be done through the XML-API. You could create a powershell script with the respective variables for the user account and a password field that the user is prompted for when they run the script. The upside to this is they can change the password by themselves and just let you know that they have change it so you can schedule a commit, the downside is even with admin roles since the API would need to run with a user given permission to alter the configuration you have to trust your users enough not to monkey with the script for any reason.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 01 Feb 2017 15:00:15 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2017-02-01T15:00:15Z</dc:date>
    <item>
      <title>Local User Database :: Password Change :: VPN Global Protect Client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/local-user-database-password-change-vpn-global-protect-client/m-p/140344#M48259</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is the a way to force the Local User change your password at the first login in the Global Protect Client?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Today I create your respective username and password but some users have been complain that I know your local respective password and they want a way to change.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Someone already had to implement something to make it easier to change that user's password without having to interfere, so I only need to pass the password once and after the first login through the global protect client he could somehow change his password.&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jan 2017 20:43:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/local-user-database-password-change-vpn-global-protect-client/m-p/140344#M48259</guid>
      <dc:creator>rbonicenha</dc:creator>
      <dc:date>2017-01-31T20:43:30Z</dc:date>
    </item>
    <item>
      <title>Re: Local User Database :: Password Change :: VPN Global Protect Client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/local-user-database-password-change-vpn-global-protect-client/m-p/140484#M48281</link>
      <description>&lt;P&gt;I don't believe that this is an option as is.&amp;nbsp;If this isn't already a feature request I would be kind of suprised, add your vote to the request through your SE or have him put a request in for it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This could potentially be done through the XML-API. You could create a powershell script with the respective variables for the user account and a password field that the user is prompted for when they run the script. The upside to this is they can change the password by themselves and just let you know that they have change it so you can schedule a commit, the downside is even with admin roles since the API would need to run with a user given permission to alter the configuration you have to trust your users enough not to monkey with the script for any reason.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2017 15:00:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/local-user-database-password-change-vpn-global-protect-client/m-p/140484#M48281</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-02-01T15:00:15Z</dc:date>
    </item>
    <item>
      <title>Re: Local User Database :: Password Change :: VPN Global Protect Client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/local-user-database-password-change-vpn-global-protect-client/m-p/140798#M48309</link>
      <description>&lt;P&gt;not at the top of my head but you can rely on third party authentication like radius, LDAP or kerberos so the users can change their passwords on those systems or use the same password as in their domain computers (which you don't know)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/62/globalprotect/globalprotect-admin-guide/set-up-the-globalprotect-infrastructure/set-up-external-authentication" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/62/globalprotect/globalprotect-admin-guide/set-up-the-globalprotect-infrastructure/set-up-external-authentication&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;Gerardo.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Feb 2017 19:58:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/local-user-database-password-change-vpn-global-protect-client/m-p/140798#M48309</guid>
      <dc:creator>glastra1</dc:creator>
      <dc:date>2017-02-02T19:58:43Z</dc:date>
    </item>
    <item>
      <title>Re: Local User Database :: Password Change :: VPN Global Protect Client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/local-user-database-password-change-vpn-global-protect-client/m-p/141205#M48362</link>
      <description>&lt;P&gt;Using external LDAP/RADIUS will not solve problem. Simplest example is when a user is outside of work for a longer period and have no possibility to update expired password onsite but have to use VPN.&lt;BR /&gt;It would be nice to have at last password change/expired password change possibility if using LDAP/Active Directory with Global Protect (without workarounds like cookies, additional cert logon etc.).&lt;/P&gt;</description>
      <pubDate>Mon, 06 Feb 2017 06:52:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/local-user-database-password-change-vpn-global-protect-client/m-p/141205#M48362</guid>
      <dc:creator>CPPalo</dc:creator>
      <dc:date>2017-02-06T06:52:38Z</dc:date>
    </item>
    <item>
      <title>Re: Local User Database :: Password Change :: VPN Global Protect Client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/local-user-database-password-change-vpn-global-protect-client/m-p/233718#M66998</link>
      <description>&lt;P&gt;This is a security issue and needs higher priority by Palo Alto.&amp;nbsp; How am I to deliver credentials to a user safely if that user isn't forced to change her password upon first login?&amp;nbsp; Every other firewall brand has this feature.&amp;nbsp; Are you telling me I have to fly from LA to Chicago to hand deliver the password?&amp;nbsp; How am I supposed to dispense credentials safely?&lt;/P&gt;</description>
      <pubDate>Wed, 03 Oct 2018 16:22:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/local-user-database-password-change-vpn-global-protect-client/m-p/233718#M66998</guid>
      <dc:creator>fkijamie</dc:creator>
      <dc:date>2018-10-03T16:22:59Z</dc:date>
    </item>
    <item>
      <title>Re: Local User Database :: Password Change :: VPN Global Protect Client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/local-user-database-password-change-vpn-global-protect-client/m-p/233725#M67002</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I'm sure there are ways to convey a password without having to hop onto a plane. I would think a phone call or text message may work?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers!&lt;/P&gt;</description>
      <pubDate>Wed, 03 Oct 2018 16:46:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/local-user-database-password-change-vpn-global-protect-client/m-p/233725#M67002</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-10-03T16:46:19Z</dc:date>
    </item>
    <item>
      <title>Re: Local User Database :: Password Change :: VPN Global Protect Client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/local-user-database-password-change-vpn-global-protect-client/m-p/233746#M67016</link>
      <description>&lt;P&gt;Fair enough, I was being a bit hyperbolic.&amp;nbsp; But, text message is out of the question because it relies on the end user to delete it.&amp;nbsp; Otherwise if the device is compromised, it has the vpn client and password on the same device.&amp;nbsp; Dictating a complex password can also be tough, especially when you are rolling out VPN access to dozens of people.&amp;nbsp; Also, best practice is to renew passwords on a periodic basis.&amp;nbsp; GlobalProtect simply doesn't have the capabilites to maintain best practice.&amp;nbsp; I guess we will have to rely on MFA for every type of user.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Oct 2018 19:01:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/local-user-database-password-change-vpn-global-protect-client/m-p/233746#M67016</guid>
      <dc:creator>fkijamie</dc:creator>
      <dc:date>2018-10-03T19:01:44Z</dc:date>
    </item>
    <item>
      <title>Re: Local User Database :: Password Change :: VPN Global Protect Client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/local-user-database-password-change-vpn-global-protect-client/m-p/233950#M67065</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I completly understand and from what I can tell it would be a nice feature. Talk to your SE and see if there is already a feature request for it. However you could use a different RADIUS server for those users and have it perform the password change?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers!&lt;/P&gt;</description>
      <pubDate>Thu, 04 Oct 2018 16:01:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/local-user-database-password-change-vpn-global-protect-client/m-p/233950#M67065</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-10-04T16:01:51Z</dc:date>
    </item>
    <item>
      <title>Re: Local User Database :: Password Change :: VPN Global Protect Client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/local-user-database-password-change-vpn-global-protect-client/m-p/233970#M67068</link>
      <description>&lt;P&gt;I'm open to workarounds.&amp;nbsp; How would this work in practice?&amp;nbsp; Tell people to first login to a public facing&amp;nbsp;web server and change their password before logging into globalprotect for the first time?&amp;nbsp;&amp;nbsp;In this scenario, what would happen if users skipped the first step and just logged into globalprotect with the initial passoword?&amp;nbsp; Would globalprotect deny access?&lt;/P&gt;</description>
      <pubDate>Thu, 04 Oct 2018 17:22:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/local-user-database-password-change-vpn-global-protect-client/m-p/233970#M67068</guid>
      <dc:creator>fkijamie</dc:creator>
      <dc:date>2018-10-04T17:22:08Z</dc:date>
    </item>
    <item>
      <title>Re: Local User Database :: Password Change :: VPN Global Protect Client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/local-user-database-password-change-vpn-global-protect-client/m-p/234112#M67109</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;From my experience, the password change option gets passed from the RADIUS server to the PAN then GP prompts the end user. Kind of like when windows on a domain asks you to change your password. I have seen this work with multi factor authentication where the user is asked to either create/change a pin for their token and/or change their password on first logon.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Oct 2018 13:33:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/local-user-database-password-change-vpn-global-protect-client/m-p/234112#M67109</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-10-05T13:33:38Z</dc:date>
    </item>
    <item>
      <title>Re: Local User Database :: Password Change :: VPN Global Protect Client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/local-user-database-password-change-vpn-global-protect-client/m-p/234527#M67230</link>
      <description>&lt;P&gt;Otakar,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks, that is exactly the solution I was looking for.&amp;nbsp; Our SE also confirmed this is now supported and provided the following link:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/41/globalprotect/globalprotect-app-new-features/new-features-released-in-gp-agent-4_1/expired-active-directory-password-change-for-remote-users" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/41/globalprotect/globalprotect-app-new-features/new-features-released-in-gp-agent-4_1/expired-active-directory-password-change-for-remote-users&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for all of your help!&lt;/P&gt;</description>
      <pubDate>Tue, 09 Oct 2018 00:41:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/local-user-database-password-change-vpn-global-protect-client/m-p/234527#M67230</guid>
      <dc:creator>fkijamie</dc:creator>
      <dc:date>2018-10-09T00:41:19Z</dc:date>
    </item>
  </channel>
</rss>

