How to update cached credentials for remote users with ADSelfService Plus

How to update cached credentials for remote users with ADSelfService Plus

Remote users' password challenges

Remote employees may often work in a different time zone than the IT team. In such a situation, if a remote employee forgets their password, they could be stranded for hours, unable to log in to their machine for an entire day or clock in to record their work hours. This isn't good for the user's productivity. ADSelfService Plus enables AD password reset for remote users and updates the cached domain credentials on their machines.

Updating the locally cached credentials on Windows machines using ADSelfService Plus can be achieved:

  • Using a VPN client
  • Without using a VPN

Organizations having VPN infrastructure with VPN vendors supported by ADSelfService Plus can update their remote users' cached credentials over VPN. When an organization does not have VPN infrastructure or uses a VPN vendor not supported by ADSelfService Plus, then they can update their remote users' cached credentials without using a VPN client.

To learn more about cached credentials, their significance, and how cached credentials update works in ADSelfService Plus, click here.

ADSelfService Plus comes bundled with a logon agent that places a Reset Password/Account Unlock button on the password change screen. When a user clicks on the password reset link, it enables them to reset their password securely and then updates their locally cached credentials.

Remote password reset: How does it work?

  1. ADSelfService Plus places a Reset Password/Account Unlock link on the login screen of Windows, macOS, and Linux machines to enable self-service password reset. Clicking this link will open thepassword reset portal.

    remote-password-reset-how-does-it-work

  2. Users are required to prove their identity through any one of the enforced authentication methods, like SMS-based one-time passwords (OTPs), email-based OTPs, Google Authenticator, DUO Security, and RSA SecurID.

    enforced-authentication-methods

    Important:

    1. Users must be enrolled in ADSelfService Plus to utilize the self-service password reset and self-service account unlock capabilities.
    2. Enrollment is a one-time process where users enter their mobile number and email address, set answers to security questions, and provide other details in ADSelfService Plus in order to register for self-service password management. Learn how to enroll users.
  3. Once a user’s identity is successfully verified, they will be allowed to reset their forgotten AD domain passwords.

    Tip: Ensure password security. Use the Password Policy Enforcer to enforce strong user passwords by including special characters and blacklisting dictionary words and patterns.

    password-policy-enforcer-screen

    • ADSelfService Plus resets the AD password and alerts the logon agent about the successful completion.
    • The logon agent initiates a request for updating the local cached credentials either through a VPN connection or without connecting to a VPN.
    • After the request is successfully approved by AD, the cached credentials are locally updated on the user's machine.

                  New to ADSelfService Plus?

                    • Related Articles

                    • Updating cached credentials in ADSelfService Plus through a custom VPN

                      ADSelfService Plus can automatically update the locally cached credentials on remote user machines as and when users reset their passwords. To update cached credentials, ADSelfService Plus requires the Windows login agent bundled with the product and ...
                    • Updating cached credentials by configuring custom VPN providers in ADSelfService Plus

                      ADSelfService Plus can automatically update the locally cached credentials in remote users’ machines as and when they reset their passwords. To update cached credentials, ADSelfService Plus requires the Windows logon agent, bundled with the product, ...
                    • How to configure and troubleshoot the cached credentials update feature

                      ManageEngine ADSelfService Plus' cached credentials update feature helps remote users reset their domain password from their login screens using the self-service password reset feature, and regain access to their Windows machines from outside the ...
                    • Microsoft 365 password reset

                      The Self-Service Password Reset (SSPR) feature in Azure AD allows users to reset their passwords without going through the help desk. However, changes to users' Azure AD passwords are only synchronized with their on-premises domain accounts when ...
                    • Google Workspace password reset

                      G Suite admins can enable users to reset their passwords and recover their accounts without admin support. ADSelfService Plus, an Active Directory (AD) self-service password management and single sign-on solution, offers the Password Reset feature, ...