Objective
This article explains how to configure the ADSelfService Plus Windows login agent (GINA/Credential Provider) to allow user logins even when the ADSelfService Plus server is unreachable. This is achieved by updating a specific bypass registry key either manually or via a Group Policy Object (GPO). This ensures users aren't locked out of their machines if the ADSelfService Plus server is down, preventing productivity loss.
Prerequisites
Steps to follow
Manual method : Update settings on a single machine
Press Windows + R to open the Run dialog box.
Type regedit and press Enter.
If prompted by User Account Control, click Yes to allow the Registry Editor to make changes.
Navigate to HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\ZOHO CORP\ADSelfService Plus Client Software.
Locate the key named Bypass.
Modify the value of Bypass to true.
Click OK.
Using a GPO: Update settings on multiple machines
Step 1: Create a new GPO
Log in to the domain controller with administrative credentials.
Press Windows + R to open the Run dialog box.
Type gpmc.msc and press Enter to open the GPMC.
On the left pane, navigate to Group Policy Objects.
Right-click Group Policy Objects and select New.
In the New GPO dialog box, enter a name for the GPO (e.g., ADSSP_LoginAgent_Bypass_Enable).
Click OK.
Step 2: Edit the newly created GPO
Right-click the GPO you just created.
Select Edit. This will open the Group Policy Management Editor.
In the Group Policy Management Editor, navigate to Computer Configuration > Preferences > Windows Settings > Registry.
Step 3: Add the registry entry to enable the login bypass
Right-click Registry on the left pane.
Navigate to New > Registry Item.
In the New Registry Properties window, configure the following:
Click Apply, then OK.
Step 4: Link the GPO
Close the editor.
Link the GPO to the relevant OU or domain.
Apply the GPO to the target machines by running the following:
gpupdate /force Validation and confirmation
Once the GPO is deployed, verify if the above settings are deployed by using the command gpresult /r.
Reboot or log out of a test client machine. Disconnect the machine from the network to simulate server unavailability. When attempting to log in, the MFA prompt should not block the login, and the user should be allowed to log in using cached credentials.
You may also check the registry on the client by navigating to HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\ZOHO Corp\ADSelfService Plus Client Software. Ensure the Bypass key exists and is set to true.
Tips
This setting is a fail-safe mechanism and should be carefully deployed in environments with intermittent connectivity.
Be cautious when configuring this setting in privileged environments to avoid account hacking scenarios.
Consider combining this GPO with monitoring and alerts to identify when fallbacks are being triggered.
How to reach support
If the issue persists, contact our support team here.