If the authentication profile is for GlobalProtect
users, enter the number of days before password expiration to start
displaying notification messages to users to alert them that their
passwords are expiring in x number of days. By default, notification
messages will display seven days before password expiry (range is
1 to 255). Users will not be able to access the VPN if their passwords
expire.
Consider configuring the GlobalProtect agents
to use the pre-logon connection method
. This will enable
users to connect to the domain to change their passwords even after
the password has expired.
If users allow their passwords
to expire, the administrator can assign a temporary LDAP password
to enable users to log in to the VPN. In this workflow, we recommend
setting the Authentication Modifier in the
portal configuration to Cookie authentication for config
refresh (otherwise, the temporary password will be used
to authenticate to the portal, but the gateway login will fail,
preventing VPN access). |