<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: &amp;quot;Enable Password Change&amp;quot; MS-CHAPv2 option and expired AD users passwords in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/quot-enable-password-change-quot-ms-chapv2-option-and-expired-ad/m-p/3456700#M537641</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jason,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the reply!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yeah, you are right, users will get prompter to change their passwords only when password has already expired. It will pop up as native windows logon client, nothing to do with ISE. Opening up the pre-auth ACL to allow them to reset their AD passwords was my first thought, but customer is reluctant to do this, since they do not want to expose their AD to unauthenticated users. I know there is an option of Read Only Domain Controller (RODC) for those who do not want to expose their AD, but customer is not eager to go this way.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I am trying to clarify what this MSHAP Enable Password Change option gives us when AD password &lt;STRONG&gt;already expired&lt;/STRONG&gt;. Will user be able to get this Windows logon client pop up and change his password?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/neverbetter" rel="nofollow" target="_blank"&gt;http://www.cisco.com/neverbetter&lt;/A&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Vadim Linev&lt;/P&gt;&lt;P&gt;ARCHITECT.SOLUTIONS&lt;/P&gt;&lt;P&gt;Cisco Services&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CCIE Security - 37396&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 08 Sep 2016 03:39:08 GMT</pubDate>
    <dc:creator>valinev</dc:creator>
    <dc:date>2016-09-08T03:39:08Z</dc:date>
    <item>
      <title>"Enable Password Change" MS-CHAPv2 option and expired AD users passwords</title>
      <link>https://community.cisco.com/t5/network-access-control/quot-enable-password-change-quot-ms-chapv2-option-and-expired-ad/m-p/3456698#M537631</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;Hi everyone!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;Can someone please clarify what exactly to expect when AD user password has expired? &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;Without any dot1x in place, on the next login user will be notified about the expired password and will be prompted by the login window itself to set the new password. Now we introduce dot1x, PEAP MS-CHAPv2, and tick 'Allowed protocols \ PEAP MS-CHAPv2 \ Enable Password Change' option on ISE. I know that this option allows changing AD password while current one is still valid, but what will happen when password is expired?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;On a side note, what are the usual/recommended way of handling users with expired passwords? Opening up pre-auth ACL (permit Kerberos to AD DCs) so password change can happen even without successful auth? &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;Thanks! &lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Sep 2016 23:29:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/quot-enable-password-change-quot-ms-chapv2-option-and-expired-ad/m-p/3456698#M537631</guid>
      <dc:creator>valinev</dc:creator>
      <dc:date>2016-09-06T23:29:33Z</dc:date>
    </item>
    <item>
      <title>Re: "Enable Password Change" MS-CHAPv2 option and expired AD users passwords</title>
      <link>https://community.cisco.com/t5/network-access-control/quot-enable-password-change-quot-ms-chapv2-option-and-expired-ad/m-p/3456699#M537635</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: -webkit-standard; font-size: medium;"&gt;Usually the password policies are set such as when to allow a user to change a password and when to expire the password. I do not believe the users got prompted to change passwords unless already expired. When not-yet-expired, they would update the passwords by other means. (Password change page facility external to ISE, you can use the ISE my devices or sponsor portals to do this by customizing it with some messaging&lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-family: -webkit-standard; font-size: medium;"&gt;)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: -webkit-standard; font-size: medium;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: -webkit-standard; font-size: medium;"&gt;Right you would need to open up the ACL that is used before user logs into the machine so they can talk to AD to do the password change. This would be at machine authentication state&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: -webkit-standard; font-size: medium;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: -webkit-standard; font-size: medium;"&gt;page 9 of this doc may help you out&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: -webkit-standard; font-size: medium;"&gt;&lt;A href="https://community.cisco.com/docs/DOC-68152"&gt;How To: Deploy ISE in Low Impact Mode&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Sep 2016 14:39:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/quot-enable-password-change-quot-ms-chapv2-option-and-expired-ad/m-p/3456699#M537635</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2016-09-07T14:39:28Z</dc:date>
    </item>
    <item>
      <title>Re: "Enable Password Change" MS-CHAPv2 option and expired AD users passwords</title>
      <link>https://community.cisco.com/t5/network-access-control/quot-enable-password-change-quot-ms-chapv2-option-and-expired-ad/m-p/3456700#M537641</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jason,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the reply!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yeah, you are right, users will get prompter to change their passwords only when password has already expired. It will pop up as native windows logon client, nothing to do with ISE. Opening up the pre-auth ACL to allow them to reset their AD passwords was my first thought, but customer is reluctant to do this, since they do not want to expose their AD to unauthenticated users. I know there is an option of Read Only Domain Controller (RODC) for those who do not want to expose their AD, but customer is not eager to go this way.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I am trying to clarify what this MSHAP Enable Password Change option gives us when AD password &lt;STRONG&gt;already expired&lt;/STRONG&gt;. Will user be able to get this Windows logon client pop up and change his password?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/neverbetter" rel="nofollow" target="_blank"&gt;http://www.cisco.com/neverbetter&lt;/A&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Vadim Linev&lt;/P&gt;&lt;P&gt;ARCHITECT.SOLUTIONS&lt;/P&gt;&lt;P&gt;Cisco Services&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CCIE Security - 37396&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Sep 2016 03:39:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/quot-enable-password-change-quot-ms-chapv2-option-and-expired-ad/m-p/3456700#M537641</guid>
      <dc:creator>valinev</dc:creator>
      <dc:date>2016-09-08T03:39:08Z</dc:date>
    </item>
    <item>
      <title>Re: "Enable Password Change" MS-CHAPv2 option and expired AD users passwords</title>
      <link>https://community.cisco.com/t5/network-access-control/quot-enable-password-change-quot-ms-chapv2-option-and-expired-ad/m-p/3456701#M537645</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Correct password change will happen. If customer doesn't want to expose AD then they will need to make sure they don't allow expiration. Would recommend they deploy a method to handle password change before this would happen and notify the user well ahead of time&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Sep 2016 14:43:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/quot-enable-password-change-quot-ms-chapv2-option-and-expired-ad/m-p/3456701#M537645</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2016-09-08T14:43:46Z</dc:date>
    </item>
  </channel>
</rss>

