Skip to main content

Password expiry warning for remote users

Problem

Remote users are not notified by Windows when their passwords are about to expire. Users who infrequently connect their laptop to the office network, instead checking email with a solution such as Outlook Web Access, suffer regular password expiry and require frequent password resets.

Solution

Bravura Pass sends users emails warning of imminent password expiry. Users change passwords using a web browser. An ActiveX control refreshes the password on their laptop.

The solution involves the following components:

Software

Purpose

Notification Service (psntfsvc)

Updates the database with information about notification events and compliance rules, and runs plugins that:

  • Check if a user is in compliance for a particular event

  • Send reminders to non-compliant users, either by web or email

  • Take action if the reminder limit for a user is exceeded

  • Generate a list of non-compliant users for batch notification

User notifications (PSN) module

Can be used to notify users of pending password expiry via a web page.

Change passwords (PSS) module

Enables users to change passwords for one or more of their accounts.

Password Manager service

Can be used to queue password changes if they fail on a target system.

Password Manager Local Reset Extension

Resets passwords and clears cached credentials on users' local workstations.

cgilocalr.exe

The program that supplies HTML to the password status page of the Change passwords (PSS) module for the S STATUS EXT plugin point.

cgilocalr.cfg

The configuration file for cgilocalr.exe.

To set up self-service password reset for remote users:

  1. Set up web-based password management features, including expiry notification.

  2. Configure Local Reset Extension .