Skip to main content

Advertise Login Assistant

If you do not install Credential Provider software on users’ workstations to allow them to access the domain help account, users must be educated to use it when they cannot remember their passwords, or when their passwords have been locked out.

There are several ways to do this:

  • Add instructions to the help desk voice response system, so that users who call for help are instructed to try to log in with the help account.

  • Configure a domain policy to display a message to users attempting to logon.

  • Deploy a login screen background image to users’ workstations, so that the instructions to try the help account are always on the users’ screens.

  • Add instructions about the help account to whatever media are distributed to users to tell them about the corporate help desk. For example, some companies print information about how to call the help desk on mouse pads.

Display message text to users at logon

You can configure Windows to display a message to users when they log on. You can customize the message to educate or remind users about the help account. The message appears after the user presses Ctrl+Alt+Del. After the user reads the message and clicks OK , they can proceed with the logon process.

The message text to display to users is configured by modifying the domain security policy.

To display a message to users at logon:

  1. On the domain controller, start the Domain Security Policy snap-in.

    On Windows 2012, click the Windows Button > Apps > Local Security Policy.

  2. Expand Security Settings > Local Policies > Security Options.

  3. In the right pane, follow these steps to create the message text:

    On a Windows Server-based domain controller:

    1. Click Interactive logon: Message title for users attempting to log on, and then type the text that you want to appear in the dialog title bar.

    2. Click Interactive logon: Message text for users attempting to log on, and then type the text that you want to appear in the body of the message.

The policy will take effect after the client has been rebooted.