<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GP-AD user password expiry in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/gp-ad-user-password-expiry/m-p/156821#M51485</link>
    <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Correct way to check password policy in AD is to run secpol.msc and show:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2017-05-16_083812.png" style="width: 765px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9272i4E42FC8D79E88D22/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2017-05-16_083812.png" alt="2017-05-16_083812.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please show this information.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Slawek&lt;/P&gt;</description>
    <pubDate>Tue, 16 May 2017 06:39:23 GMT</pubDate>
    <dc:creator>_slv_</dc:creator>
    <dc:date>2017-05-16T06:39:23Z</dc:date>
    <item>
      <title>GP-AD user password expiry</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-ad-user-password-expiry/m-p/156754#M51470</link>
      <description>&lt;P&gt;When setting up a Global policy object for a Paloalto globalprotect user/group , the maxpwdage attribute does not match the, the password expiry date sent for Paloalto user, This can be confusing to know when the password actually going to expire for the GP user.&lt;BR /&gt;Panos 7.0.6&lt;BR /&gt;Gp 3.0.3&lt;BR /&gt;AD server 2012r2&lt;BR /&gt;&lt;BR /&gt;Max password age was set on 14.05.17&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pwdpilicy.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9265iDB7A97BBEFED41E8/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="pwdpilicy.PNG" alt="pwdpilicy.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tailing the authd logs whilst connecting with a GP user&lt;BR /&gt;&amp;gt;&amp;gt;tail follow yes mp-logs authd&lt;BR /&gt;It shows that there are only 64 days left before the password expires, however the default domain policy is set to 75 days&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pwdexpiry.jpg" style="width: 651px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9266i32BB402FF6447018/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="pwdexpiry.jpg" alt="pwdexpiry.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;This difference is due to the attirbutes maxpwdage an pwdlastset were set on differnet date.&lt;BR /&gt;run the below command on windows shell&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;get-aduser -filter * -properties passwordlastset, passwordneverexpires |ft Name, passwordlastset, Passwordneverexpires&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;The output below suggests that passwordlast set for the user on 04.05.17&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pwdlastset1.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9267i9FABA09277D9A127/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="pwdlastset1.jpg" alt="pwdlastset1.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;There is a difference of 11 days between attributes &amp;nbsp;maxpwdage and pwdlastset&lt;BR /&gt;maxpwdage-passwordlast set= password expiry&lt;BR /&gt;75 -11 =64 days&lt;BR /&gt;&lt;BR /&gt;Best regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kash&lt;/P&gt;</description>
      <pubDate>Mon, 15 May 2017 20:30:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-ad-user-password-expiry/m-p/156754#M51470</guid>
      <dc:creator>Kashif_Noor</dc:creator>
      <dc:date>2017-05-15T20:30:54Z</dc:date>
    </item>
    <item>
      <title>Re: GP-AD user password expiry</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-ad-user-password-expiry/m-p/156821#M51485</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Correct way to check password policy in AD is to run secpol.msc and show:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2017-05-16_083812.png" style="width: 765px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9272i4E42FC8D79E88D22/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2017-05-16_083812.png" alt="2017-05-16_083812.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please show this information.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Slawek&lt;/P&gt;</description>
      <pubDate>Tue, 16 May 2017 06:39:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-ad-user-password-expiry/m-p/156821#M51485</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2017-05-16T06:39:23Z</dc:date>
    </item>
  </channel>
</rss>

