Active Directory Password Changes using GlobalProtect

Active Directory Password Changes using GlobalProtect

171995
Created On 09/25/18 17:36 PM - Last Modified 07/30/20 17:24 PM


Symptom


AD policies and passwords

There are often situations where Active Directory (AD) policies require users to change passwords, for example, the first time a user logs in with a temporary password, when a user’s password expires, or when a user forgets a password. Unfortunately, because enterprises typically do not expose their Active Directory infrastructure over the internet, remote users may not have the access they need to update their AD passwords in these situations.


Environment


  • PAN-OS
  • GlobalProtect (GP)


Cause


Enabling password change for remote users

  • GlobalProtect 3.1 and earlier versions do not natively provide support to change or update a user’s AD password.
  • This document explains how you can use alternate methods and enable remote users to change their Active Directory passwords over a GlobalProtect tunnel.


Resolution


Workarounds using GlobalProtect VPN tunnel

GlobalProtect 3.1 and earlier versions do not natively provide support to change or update a user’s AD password. However, you can configure alternate authentication methods besides Active Directory that will enable remote users to establish a GlobalProtect VPN tunnel. Once the tunnel has been established and users can reach the enterprise Active Directory, they can change their password even when working remotely.

GlobalProtect supports two configuration options that enable remote users with the necessary access to
change their AD password:
  1. A pre-logon connect method that creates a machine-level VPN tunnel using a machine certificate.
  2. GlobalProtect Authentication override that enables cookie-based authentication.

Using one of these options, you can prevent remote users from being locked out when they forget their password or when their password expire. 

A remote user may try to change or update their password at 2 different times:

  1. At the time of logging in to the Windows system
  2. After logging in to the Windows system

 

Enabling remote users to change password at Windows Login

Pre-logon is one of the Connect Methods supported by GlobalProtect. Pre-logon enables GlobalProtect to establish a VPN tunnel using a machine certificate on the user’s endpoint (computer, laptop, or notebook). This connection method establishes a pre-logon tunnel immediately after the system boots up and before the user logs in. If the enterprise AD is accessible over this pre-logon tunnel, remote users can log in to the domain with a temporary password or use the Change Password option that's natively available on the Windows login screen to update their passwords.

 
This option is particularly useful if a remote user forgets the Active Directory credentials and is unable to log in even to the Windows system. Without the pre-logon tunnel, even if the administrator resets the user's password, the remote user cannot use the new password to log in to the domain and subsequently update the password.
For more information on the pre-logon connect method, refer to Remote Access VPN with Pre-Logon.
 
Because of the changes Microsoft has made to the Windows login and the credential provider framework, the end user experience to change their AD password remotely at the time of Windows login is different in Windows 7 and Windows 8 / Windows 10.
 

Changing AD password on Windows 7:

On Windows 7, GlobalProtect credential provider wraps the native Windows credential provider and providesthe end user with native Windows login experience. So user can login as they normally do and any passwordpolicy that's enforced by AD gets applied and user is notified about the password requirements as usual.
 

Changing AD password on Windows 8 and 10:

However on Windows 8 and Windows 10, ability to change password is not available if users selectGlobalProtect as the sign-in option. Users have to set Windows as the default sign-in option before using a temporary AD password and subsequently change their AD password while logging in remotely.
 
GlobalProtect Single Sign On (SSO) would fail after the user sets Windows as the default sign-in option. The user must log out from Windows, then choose GlobalProtect as the sign-in option while signing in to Windows to get GlobalProtect SSO to work again.
 
For more details on SSO for GlobalProtect refer to Single Sign-On (SSO) for GlobalProtect
 

Enabling remote users to change password after logging in to Windows

If the remote user remembers the AD credentials but the password has expired, the user would still be able to login to the Windows system using cached credentials. However authentication to the portal or gateway would fail because the AD password has expired. In this scenario you could use the GlobalProtect authentication override feature (introduced in PAN OS 7.1 and GlobalProtect 3.0). This feature enables GlobalProtect portalsand GlobalProtect gateways to override the authentication profile requirements and authenticate users with acookie instead. To use this option, you must do the following:
  1. Configure the GlobalProtect portal to generate a cookie and accept the cookie for authentication.
  2. Configure at least one GlobalProtect gateway to accept the cookie for authentication.
  3. Set the lifetime of the cookie to as long as you would want the user to be able to login to this gateway even after the user's password has expired.

With this configuration, even if the password has expired, a remote user will still be able to get connected to this gateway using the cookie as long as it is still valid. After the tunnel is established, remote users can reach the enterprise Active Directory and change their passwords by pressing Ctrl + Alt + Delete and using the change password option.

For more information on cookie-based authentication, refer to Enhanced Two-FactorAuthentication.

 

Workarounds to enable remote users to change AD passwords using GlobalProtect

Although GlobalProtect does not natively support Active Directory password changes, you can configure
GlobalProtect to enable remote users to change their Active Directory passwords.
  • The pre-logon connection method is particularly useful if the user is logging into the domain for the first time or has a temporary password for the domain.
  • The authentication override is useful if the user's password has expired and the user is still able to log in to the endpoint using cached credentials.

 

 



Additional Information




Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGYCA0&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language