Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

For AD user password reset option

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Palo Alto Networks Approved
Palo Alto Networks Approved
Community Expert Verified
Community Expert Verified

For AD user password reset option

L2 Linker
We have seen that whenever a domain password is  going to expire for the SSL VPN user, the Global Protect client on the user's system starts flashing a message that the password will expire soon. We want to know if there is any possibility to embed a password reset link as well along with such a message.
Please help us on the same so that we convey it to the end users.
There is any option in global protect for reset AD password.
4 REPLIES 4

Cyber Elite
Cyber Elite

Hello

 

Within the client config is this option

 

SteveCantwell_0-1624464724323.png

 

So I do believe it is possible to put in a link.

 

As far as a reset link.. the immediate answer is no..... but then, if you decide to implement with pre-login (which creates a VPN before a user even logs onto the computer) would allow a way to change the password.  The computer would already be connected to the domain, and then the user can reset the password right on the login page of the Windows machine.

Help the community: Like helpful comments and mark solutions

Cyber Elite
Cyber Elite

@SurajN,

Just to expand on @S.Cantwell's answer a bit, if you have a self-service portal you can utilize the custom message to provide a link to that resource to allow folks to change their password prior to it being expired. 

If you want to allow a user to change an expired password utilizing GlobalProtect without having to setup a pre-login, you can actually do this directly through GlobalProtect. You need to be utilizing RADIUS authentication and setup PEAP-MSCHAPv2 as your auth protocol, but if setup properly it'll allow a user to actually change their AD password. You can view information on how to set that up HERE

The link is dead for some reason.

Community Team Member

Hi @B.Alimov ,

 

So about that document ... yeah the link is dead because it's pointing towards an end-of-life version of the page.  However, I think I can help you with that.

 

EOL guides are also posted in PDF format. Here is the 4.1 guide: https://docs.paloaltonetworks.com/content/dam/techdocs/en_US/pdf/globalprotect/4-1/globalprotect-app...

 

To get to the EOL Resources page: https://docs.paloaltonetworks.com/resources/eol

From here you can filter on product, version, etc...

 

Hope this helps,

-Kim.

LIVEcommunity team member, CISSP
Cheers,
Kiwi
Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.
  • 3036 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!