<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Anyone use &amp;quot;Expired Active Directory Password Change for Remote Users&amp;quot; in PAN version in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/anyone-use-quot-expired-active-directory-password-change-for/m-p/218161#M63073</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/31654"&gt;@_slv_&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Yes, the pre-logon feature can be used for password changes or setting a new password when the user is required to. But if you use also the single sign ln feature you have to choose the Global Protect login option and if this option is chosen, passeord reset/change no longet work so the user has to change back to the default login option to change the password and after that he has to change again to the global protect login option to make single sign on work again...&lt;/P&gt;&lt;P&gt;... this works for IT people, but not for "normal" users who would then call the hotline every time ... so this feature sounds good with the password change in the GP application, but I did not test it so far.&lt;/P&gt;</description>
    <pubDate>Sun, 17 Jun 2018 17:41:45 GMT</pubDate>
    <dc:creator>Remo</dc:creator>
    <dc:date>2018-06-17T17:41:45Z</dc:date>
    <item>
      <title>Anyone use "Expired Active Directory Password Change for Remote Users" in PAN version 8.1 and GP Ver</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/anyone-use-quot-expired-active-directory-password-change-for/m-p/216737#M62757</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Anyone use "Expired Active Directory Password Change for Remote Users" in PAN version 8.1 and GP Version 4.1?&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/41/globalprotect/globalprotect-app-new-features/new-features-released-in-gp-agent-4_1/expired-active-directory-password-change-for-remote-users" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/41/globalprotect/globalprotect-app-new-features/new-features-released-in-gp-agent-4_1/expired-active-directory-password-change-for-remote-users&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Does it work? Can you do it with LDAP or do you have to use radius? Any gotchas?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jun 2018 21:33:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/anyone-use-quot-expired-active-directory-password-change-for/m-p/216737#M62757</guid>
      <dc:creator>junior_r</dc:creator>
      <dc:date>2018-06-05T21:33:36Z</dc:date>
    </item>
    <item>
      <title>Re: Anyone use "Expired Active Directory Password Change for Remote Users" in PAN version</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/anyone-use-quot-expired-active-directory-password-change-for/m-p/218159#M63071</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have the same problem as You...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it possibly that noone is using prelogon feature for password reset?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For what reason we have Radius connection? Is it nessesary for AD password change according to &lt;A href="https://www.paloaltonetworks.com/documentation/41/globalprotect/globalprotect-app-new-features/new-features-released-in-gp-agent-4_1/expired-active-directory-password-change-for-remote-users.html" target="_self"&gt;this link&lt;/A&gt;?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please help us!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Slawek&lt;/P&gt;</description>
      <pubDate>Sun, 17 Jun 2018 17:20:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/anyone-use-quot-expired-active-directory-password-change-for/m-p/218159#M63071</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2018-06-17T17:20:49Z</dc:date>
    </item>
    <item>
      <title>Re: Anyone use "Expired Active Directory Password Change for Remote Users" in PAN version</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/anyone-use-quot-expired-active-directory-password-change-for/m-p/218161#M63073</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/31654"&gt;@_slv_&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Yes, the pre-logon feature can be used for password changes or setting a new password when the user is required to. But if you use also the single sign ln feature you have to choose the Global Protect login option and if this option is chosen, passeord reset/change no longet work so the user has to change back to the default login option to change the password and after that he has to change again to the global protect login option to make single sign on work again...&lt;/P&gt;&lt;P&gt;... this works for IT people, but not for "normal" users who would then call the hotline every time ... so this feature sounds good with the password change in the GP application, but I did not test it so far.&lt;/P&gt;</description>
      <pubDate>Sun, 17 Jun 2018 17:41:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/anyone-use-quot-expired-active-directory-password-change-for/m-p/218161#M63073</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-06-17T17:41:45Z</dc:date>
    </item>
    <item>
      <title>Re: Anyone use "Expired Active Directory Password Change for Remote Users" in PAN version</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/anyone-use-quot-expired-active-directory-password-change-for/m-p/218163#M63075</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't use SSO for GP (most out laptops are not AD joined) but those users from such laptops conect to computers that are joined to AD (RDP connection).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;According &lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/Basic-GlobalProtect-Configuration-with-Pre-logon/ta-p/136131" target="_self"&gt;to link &lt;/A&gt;I think that pre-logon feature is not for me...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thx for explanation!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Slawek&lt;/P&gt;</description>
      <pubDate>Sun, 17 Jun 2018 18:03:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/anyone-use-quot-expired-active-directory-password-change-for/m-p/218163#M63075</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2018-06-17T18:03:53Z</dc:date>
    </item>
  </channel>
</rss>

