Domain Password Expiration When Using an RDS Server Published App

DGC 26 Reputation points
2020-11-06T09:31:54.727+00:00

Hello

We have recently put in place a password policy on our domain which requires regular changes of users passwords.

We have a Windows RDS Server 2012 R2 from which we publish our SAP program for remote users to use as we don't want them to use a VPN and connect directly in and use a complete user profile. This all works absolutely fine, however since putting in place the password policy it has created a problem. Namely when their passwords expire, they simply can't login, no message, warning or anything.

If I log in the "old fashioned" way by VPN and logging into the RDS server so that I have a user profile, then when the password is about to expire, I get the warning message saying there's so many days until your password expires click here to change it, whereby if I click on the message at the bottom of the screen I can change my password. However, with connecting to the published app I don't get any message/option to change password, it just expires and I can't log in. Is there any setting I can enable to allow this to happen, or has anyone found a workaround for this, or is it simply that it can't be done.

Any help gratefully received.

Thanks.

DGC

Windows
Windows
A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.
4,798 questions
Windows Server 2012
Windows Server 2012
A Microsoft server operating system that supports enterprise-level management, data storage, applications, and communications.
1,534 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,932 questions
Remote Desktop
Remote Desktop
A Microsoft app that connects remotely to computers and to virtual apps and desktops.
4,260 questions
0 comments No comments
{count} vote

Accepted answer
  1. Karlie Weng 14,641 Reputation points Microsoft Vendor
    2020-11-10T05:54:25.78+00:00

    Hello DGC @DGC

    Domain policy can apply over VPN connection, but not sure in other way.

    If you have to use SAP , you can create password reset option in RD Web access :

    Here’s how enabling the RD WebAccess Expired password reset option

    Allow Users to Change Expired Password via Remote Desktop Web Access on Windows Server 2016/2012R2

    ----------

    If the Answer is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    Best Regards
    Karlie


4 additional answers

Sort by: Most helpful
  1. Thameur-BOURBITA 32,586 Reputation points
    2020-11-06T12:53:34.88+00:00

    Hi,

    You can create a web site to let users change password because some clients don't offer the option to change the password and let user autonomous to manage the change of its password

    Please don't forget to mark this reply as answer if it help you to fix tour issue

    0 comments No comments

  2. Karlie Weng 14,641 Reputation points Microsoft Vendor
    2020-11-09T06:55:20.09+00:00

    Hey @DGC

    Is there any other domain policy set? Does them work after publishing SAP program?

    Is the domain group policy set related to user profiles ?

    Keep me posted how it goes.

    Thank you and have a great day!

    ----------

    If the Answer is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    Best Regards
    Karlie

    0 comments No comments

  3. DGC 26 Reputation points
    2020-11-09T09:30:52.307+00:00

    Hi Karlie

    There are other policies in place, but the password policy is only set in one policy. They work fine on the published app, none of the other policies affect them, they are all for PC's on the local network.

    I've just checked, the password policy is set in the 'Computer Configuration' section not the 'User Configuration' section. I've looked in the 'User Configuration' at 'security settings' and it contains a lot less options, the 'account policies' part doesn't exists. Is this the problem?

    Thanks.

    DGC

    0 comments No comments

  4. DGC 26 Reputation points
    2020-11-16T16:02:14.053+00:00

    Hi Karlie

    Apologies for the delay in responding, I've been on annual leave.

    That worked perfectly.

    Many thanks.

    DGC

    0 comments No comments