OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: Forcing Password Changes for Non-Interacitve Logons

From: Mark Holmes (mark.holmesnuffield.ox.ac.uk)
Date: Mon Jul 20 2009 - 17:55:04 CDT


Hi,

We have a similar issue at my place - not all users are joined to the
domain, so don't do an interactive logon. I use a vb script which
runs nightly and checks AD for users whose password is due to expire,
it sends email reminders 14 7 3 and 2 days before expiry via email
(pulls the users address from AD). They then go to a secure page on
our intranet to change their password.

Cheers,

Mark

On 20 Jul 2009, at 23:32, "GrowlieGirlgmail.com"
<GrowlieGirlgmail.com> wrote:

> I have googled and googled but cannot find the answer to this one,
> hoping you can help.
> We have ADS password policy enforced whereby the user has to change
> their password every 60 days. If they have not changed their
> password after this time their account is locked. Unfortunately the
> users with non-interactive accounts do not get the notification to
> change their password nor can they get to the change password
> facility that the interactive logon users can use. Is there any way
> to notify the users and have them carry out a password change?

On 20 Jul 2009, at 23:32, "GrowlieGirlgmail.com"
<GrowlieGirlgmail.com> wrote:

> I have googled and googled but cannot find the answer to this one,
> hoping you can help.
> We have ADS password policy enforced whereby the user has to change
> their password every 60 days. If they have not changed their
> password after this time their account is locked. Unfortunately the
> users with non-interactive accounts do not get the notification to
> change their password nor can they get to the change password
> facility that the interactive logon users can use. Is there any way
> to notify the users and have them carry out a password change?
>