Using Active Directory to Force the User to Change Password at Next Logon

To force a user to change the user password at the next logon, specify the password-management command in tunnel-group general-attributes configuration mode on the security appliance and do the following steps under Active Directory:

Step 1 Select to Start > Programs > Administrative Tools > Active Directory Users and Computers (Figure 30-1).

Figure 30-1 Active Directory—Administrative Tools Menu

Figure 30-1 Active Directory—Administrative Tools Menu

Active Directory Tools Menu

Step 2 Right-click Username > Properties > Account.

Step 3 Check the check box for User must change password at next logon (Figure 30-2).

Figure 30-2 Active Directory— User Must Change Password at Next Logon

Guest Properties

Jjxj

Published Certificates j Member Of j Dial-in ) Object | Security Environment | Sessions ] Remote control Terminal Services Profile Exchange Features

General | Address Account | Profile | Telephones ] Organization

User logon name: I Guest

User logon name (pre-Windows 2000): |FRDEVTESTAD\

|@FrDevTestAD.Iocal

|Guest

Logon Hours..

r Account is locked out Account options:

Fi User must change password at next logon

User cannot change password [I- Password never expires

Store password using reversible encryption d

Cancel

Apply

Help

The next time this user logs on, the security appliance displays the following prompt: "New password required. Password change required. You must enter a new password with a minimum length n to continue." You can set the minimum required password length, n, as part of the Active Directory configuration at Start > Programs > Administrative Tools > Domain Security Policy > Windows Settings > Security Settings > Account Policies > Password Policy. Select Minimum password length.

Continue reading here: Using Active Directory to Specify Maximum Password Age

Was this article helpful?

0 0

Readers' Questions

  • lorenza
    What does user must change password at next logon?
    7 months ago
  • When a user is required to change their password at their next login, it means that the system administrator has enabled password complexity and expiration policies, requiring users to periodically change their passwords to maintain security. This type of policy helps to prevent hackers from guessing passwords, or using stolen credentials to access an organization's systems.