Educause Security Discussion mailing list archives

Re: Change Password on Next Login via Web


From: "Dr. Wole Akpose" <wole.akpose () MORGAN EDU>
Date: Tue, 26 Apr 2011 22:35:16 -0400

what version of forefront are you using? 2010 includes password notifier.

I sense you first want users to authenticate and then change password later.
If this is true, why?

How is your forefront architected. Do you currently use the self server
features of forefront?

W. Akpose
On Apr 26, 2011 9:19 PM, "Matt Giannetto" <MGiannetto () mc3 edu> wrote:
Folks,

We’re trying to improve our registration process via the web and are
running into a roadblock. I’m hoping I can poll the group and find out how
other schools are tackling this problem.

Our goal is to be able to have the ability to force users to change their
password on first/next login after they authenticate to our SharePoint web
portal. The big limitation we’re currently running into is that when the
“Change password on next login” is flagged in Active Directory, all of our
web services consider the account as locked and won’t let them authenticate.
We’re also looking for something that can help facilitate password
expiration, such as emailing the user, "Your password will change in X
number of days, please click here to change it". If it makes a difference,
we also use Forefront Identity Management.

We currently use Courion to manage self-service password resets. I’ve
reached out to them to see if their product could help us tackle this issue,
but unfortunately it does not.

We’re looking for a technique or a tool that can help us get past this
issue. Any advice?

Thanks,

Matt Giannetto
Director of IT Security
Montgomery County Community College
mgiannetto () mc3 edu | (215) 619-7442

Montgomery County Community College is proud to be
the #1 ranked technology-savvy community college in the nation,
as determined by the Center for Digital Education and Converge magazine.

Current thread: