Site icon WinCert

Cannot change passwords through RDP connection

<p>One of our clients reported a problem regarding the change of expired passwords through RDP connection&period;<&sol;p>&NewLine;<p>Some users are connecting to jump stations and they do not have any other access to local company resources&period;<&sol;p>&NewLine;<p>Once the password for a domain account expire those users do not have the option to change the password via RDP connection&period;<&sol;p>&NewLine;<p>Users get the following error message&colon;<br &sol;>&NewLine;An authentication error has occurred&period; The Local Security Authority cannot be contacted&period;<br &sol;>&NewLine;Remote computer&colon;<br &sol;>&NewLine;This could be due to an expired password&period;<br &sol;>&NewLine;Please update your password if it has expired&period;<br &sol;>&NewLine;For assistance&comma; contact your administrator or technical support&period;<&sol;p>&NewLine;<p><img class&equals;"alignnone wp-image-2685 size-full" title&equals;"passwords through RDP" src&equals;"https&colon;&sol;&sol;www&period;wincert&period;net&sol;wp-content&sol;uploads&sol;2018&sol;08&sol;rdp&lowbar;nla&lowbar;1&period;png" alt&equals;"passwords through RDP" width&equals;"406" height&equals;"207" &sol;><&sol;p>&NewLine;<p>To be able to fix this I had to lower down security on one of those jump stations so users are able to change the password only on one jump station&period; Users will also have to change the <strong>&period;rdp<&sol;strong> file with instructions below&period; After that&comma; they will be able to normally connect to other jump stations they have access to&period;<&sol;p>&NewLine;<ol>&NewLine;<li>Open Remote Desktop Connection &lpar;<strong>mstsc&period;exe<&sol;strong>&rpar;<&sol;li>&NewLine;<li>Under <strong>Show Options<&sol;strong> &vert; <strong>Connection settings<&sol;strong> &vert; Click <strong>Save as<&sol;strong> to save the <strong>&ast;&period;rdp<&sol;strong> file<&sol;li>&NewLine;<li>Right click on the <strong>&period;rdp<&sol;strong> file and edit this file with <strong>Notepad<&sol;strong> or other text editors<&sol;li>&NewLine;<li>Add the following line&colon; <strong>enablecredsspsupport<&sol;strong><strong>&colon;i&colon;0<&sol;strong><&sol;li>&NewLine;<li>Save the file<&sol;li>&NewLine;<&sol;ol>&NewLine;<p><img class&equals;"alignnone size-full wp-image-2688" src&equals;"https&colon;&sol;&sol;www&period;wincert&period;net&sol;wp-content&sol;uploads&sol;2018&sol;08&sol;rdp&lowbar;nla&lowbar;3&period;png" alt&equals;"" width&equals;"289" height&equals;"151" &sol;><&sol;p>&NewLine;<p>When you try to connect now you might receive another error message&colon;<&sol;p>&NewLine;<p>The remote computer requires Network Level Authentication&comma; which your computer does not support&period; For assistance&comma; contact your system administrator or technical support&period;<&sol;p>&NewLine;<p><img class&equals;"alignnone wp-image-2687 size-full" title&equals;"passwords through RDP" src&equals;"https&colon;&sol;&sol;www&period;wincert&period;net&sol;wp-content&sol;uploads&sol;2018&sol;08&sol;rdp&lowbar;nla&lowbar;2&period;png" alt&equals;"passwords through RDP" width&equals;"557" height&equals;"133" &sol;><&sol;p>&NewLine;<p>Now&comma; go to the destination <strong>server&sol;jump station<&sol;strong> and do the following&period;<&sol;p>&NewLine;<p>Open <strong>local security editor<&sol;strong> &lpar;<strong>gpedit&period;msc<&sol;strong>&rpar; and browse to the following setting&colon;<&sol;p>&NewLine;<h6>Computer Configuration &vert; Administrative Templates &vert; Windows Components &vert; Terminal Services &vert; Terminal Server &vert; Security<&sol;h6>&NewLine;<p><em>Note&colon; The path used is for Windows 2008 server&period; On other Windows Servers&comma; it might be slightly different&period;<&sol;em><&sol;p>&NewLine;<p>Change the <strong>Require user authentication for remote connections by using Network Level Authentication<&sol;strong> setting to <strong>Disabled<&sol;strong>&period;<&sol;p>&NewLine;<p>Close the policy editor and try to connect again&period; Users should now be able to change expired passwords through RDP connection&period;<&sol;p>&NewLine;<p>Hope this helps&period;<&sol;p>&NewLine;

Exit mobile version