- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
01-19-2024 10:30 AM
Just wanted to share in case others run into this. My company has recently started to use Microsoft's SSPR process which is embedded into the Windows 10/11 OS.
Specifics on how it works here: Self-service password reset for Windows devices - Microsoft Entra ID | Microsoft Learn
This specific section is going to be an issue for GP VPN environments with always on VPN with user authentication enforcement for the VPN tunnel:
"When users reset their password from the sign-in screen of a Windows 11 or 10 device, a low-privilege temporary account called defaultuser1
is created. This account is used to keep the password reset process secure.
The account itself has a randomly generated password, which is validated against an organizations password policy, doesn't show up for device sign-in, and is automatically removed after the user resets their password. Multiple defaultuser
profiles may exist but can be safely ignored."
With this action the GP client sees this user account logging into the OS. Since this user is a local machine user and isn't a known user to GP's auth profile the user tunnel on VPN will fail which means the VPN is disconnected with no way for the user to complete the SSPR process.
Right now we're exploring creating a secondary authentication profile (Creating this account as local to the firewall/PAN) for GP which will include this user somehow in the hopes that the SSPR process doesn't break the VPN connectivity.
When we get this figured out I'll post the technical solution.
01-19-2024 03:00 PM
Thanks @Brandon_Wertz , looking forward to your next post!
03-21-2024 02:50 AM
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!