No answer found for the above. Basically if VPN is user tunnel and not an always on VPN users who forget passwords or have passwords expire would have to return to the company LAN and logon direct to the company network to reset\have their passwords reset.
Windows Domain Passwords Expiration and Windows hello for business and network resource access
Having setup in a hybrid environment (AD on premises and Azure AD) user domain accounts that have a password expiration of 45 days and users can logon to the domain on client devices using Biometric logon or Windows username and PIN logon or standard username and their domain password logon, what happens when the 45 day limit approaches and passes, if say for example, a domain a user is always just using biometric logon or simply ignores the password is to expire prompt to change (and if using biometric would they still see the password expire prompt to change at all or is that warning only seen if they actually use a password to logon) ? On day 46 can the user still logon with biometric or PIN and also hyen still access all network resources as normal (both on premises and cloud resources i.e. e-mail, onedrive, MS Teams etc) or does the password expiration allow logon but prevent access to the network resources ?
Further if a user is working remotely (at home) and has say Fortinet client VPN and that is just a user VPN tunnel i.e. not active until logon and thus not an always on VPN, then if their password expired or they simlpy have forgotten it as they dont use it often or at all to logon, can they recover from that remotely or would they need to visit site. If we have Self Service Password reset can they go to the portal and change the password, and would that be of any use anyway once changed, if they still cannot remember the old password that is cached on their system as their VPN is not active until logon ?
Microsoft Security | Microsoft Entra | Microsoft Entra ID
3 answers
Sort by: Most helpful
-
-
Skype228 16 Reputation points
2022-06-08T14:56:53.297+00:00 Not received any replies yet to question.
-
Josh M. Jacobs 1 Reputation point
2022-12-14T19:30:21.787+00:00 @Skype228 have you found any answer or solution to this?