{"id":34831,"date":"2021-05-25T11:00:00","date_gmt":"2021-05-25T15:00:00","guid":{"rendered":"https:\/\/jumpcloud.com\/?p=34831"},"modified":"2024-11-14T17:19:37","modified_gmt":"2024-11-14T22:19:37","slug":"sync-active-directory-vpn","status":"publish","type":"post","link":"https:\/\/jumpcloud.com\/blog\/sync-active-directory-vpn","title":{"rendered":"Syncing Active Directory Passwords Remotely: Two Common Problems"},"content":{"rendered":"\n

With remote work dominating during the global COVID crisis, a key issue that IT organizations have been facing is how to update Active Directory passwords. Generally, after 90 days, the password within AD needs to be updated and if this isn\u2019t done, the end user can be completely detached from the domain. Most IT admins haven\u2019t had to deal with this issue very often because most users are connected to the domain and are in the office, so handling this historically has been simple; but, now with remote work, this problem can present quite the challenge to the end user and employee.<\/p>\n\n\n\n

Generally, Microsoft\u00ae<\/sup> Active Directory\u00ae<\/sup><\/a> (AD) passwords are updated over a VPN. It seems like these two pieces of core infrastructure (AD and a VPN) should work together seamlessly, but usually they don\u2019t integrate as you\u2019d expect. We\u2019ll address two common challenges below: syncing a user\u2019s local OS password with their AD domain password remotely (which often requires a VPN), and syncing VPN authentication\/access with AD to minimize the number of sets of credentials a user must manage. <\/p>\n\n\n\n

Problem 1: Remote User Password Resets with AD via VPN<\/h2>\n\n\n\n

Your organization\u2019s security rules may require users to change their AD passwords every 90 days. And every 90 days, that on-prem rotation leaves your remote employees in the dust – which today constitutes just about everybody. They\u2019re glad they rarely have to come into the office, but then they\u2019re frustrated when they find that their domain password has expired. Many times in this scenario an end user could be locked out of their machine and if their AD password is the same as their VPN password, then they can\u2019t login to the domain at all and they are completely locked out. Now you\u2019re on the phone with one of them, and you have to talk through the fix. This is an especially acute problem with macOS endpoints.<\/p>\n\n\n\n

Assuming that the user can still login to their machine, they will need to: <\/p>\n\n\n\n

    \n
  1. Connect to their organization\u2019s infrastructure via a VPN. This connection provides access to the on-prem directory, Active Directory. <\/li>\n\n\n\n
  2. Next, they should log off of the machine. (As long as the VPN client is running as a service, logging off shouldn\u2019t interrupt the session.) <\/li>\n\n\n\n
  3. Now the user can log back onto the device by updating their credentials. <\/li>\n<\/ol>\n\n\n\n

    This solution can be confusing because the user needs their old credentials to gain initial access to AD so that AD can then sync the new credentials to the device. It\u2019s not a particularly efficient process, but it works. For Macs, though, this process is far from seamless. And, as stated above, if the user\u2019s VPN password has expired as well, the user will likely need your intervention to get back up and running.<\/p>\n\n\n\n

    \n
    \n \"JumpCloud\"\n <\/div>\n
    \n

    \n Breaking Up with Active Directory <\/p>\n

    \n Don\u2019t let your directory hold you back. Learn why it\u2019s time to break up with AD. <\/p>\n <\/div>\n

    \n Read Now<\/a>\n <\/div>\n<\/div>\n\n\n\n\n

    Problem 2: Sync VPN Access with AD Credentials <\/h2>\n\n\n\n

    When security measures start to hamstring a user\u2019s workflow, that user is more likely to bypass them and compromise your network for the sake of efficiency. We see this constantly with login credentials: people get overwhelmed by the number of passwords to their basic IT resources and start to duplicate passwords or store them insecurely. Research on the human factor<\/a> in identity security indicates that even users who are informed about the risks will sometimes sacrifice security in the name of convenience, especially when they feel the consequences of a breach wouldn\u2019t impact them personally. <\/p>\n\n\n\n

    (To learn more about how well-meaning employees on the inside of organizations have gradually become one of the weakest links in IT security, check out our article on Why It\u2019s Time to Take Identity Security Seriously<\/a>. We also have tips for training employees to be more vigilant in Security Training 101<\/a>.)<\/p>\n\n\n\n

    With this human bias toward convenience in mind, it\u2019s no wonder that you and your IT team are working diligently to reduce the number of passwords needed, while increasing their security and strength. VPN access is among the most annoying of these sticking points, so naturally you want to sync AD credentials with your VPN access. In this scenario, a user\u2019s AD credentials would also grant them VPN access, and the two authentication systems would always stay synced, even after password changes and updates. Unfortunately, a DIY solution that fully achieves this ends up being easier said than done.<\/p>\n\n\n\n

    An Elegant Solution to Sync AD with VPN<\/h2>\n\n\n\n

    Given the above roadblocks to syncing AD with a VPN, you might be wondering what a more streamlined solution would look like. Instead of building patches that would solve each specific problem individually, what if you could zoom out and fundamentally modernize the way Active Directory passwords sync<\/a> with your VPN, solving both of these problems at once? A cloud-based directory service could integrate with Active Directory to offer different sets of solutions based on your needs.\u00a0<\/p>\n\n\n\n

    Learn more about how JumpCloud AD Integration works<\/a> to maximize your network\u2019s security and efficiency. Or, if you\u2019d rather see how this all looks from the driver\u2019s seat, you can sign up for a trial of JumpCloud<\/a> and integrate your AD credentials with your non-domain-bound IT infrastructure.<\/p>\n","protected":false},"excerpt":{"rendered":"

    Learn how to sync a remote user\u2019s AD password, which usually requires a VPN, and how to sync VPN authentication to your central directory.<\/p>\n","protected":false},"author":120,"featured_media":34833,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_oasis_is_in_workflow":0,"_oasis_original":0,"_oasis_task_priority":"","inline_featured_image":false,"footnotes":""},"categories":[2781],"tags":[],"collection":[2777],"platform":[],"funnel_stage":[3015],"coauthors":[2537],"acf":[],"yoast_head":"\nSyncing AD Passwords Remotely: Two Common Problems - JumpCloud<\/title>\n<meta name=\"description\" content=\"Learn how to sync a remote user\u2019s AD password, which usually requires a VPN, and how to sync VPN authentication to your central directory.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/jumpcloud.com\/blog\/sync-active-directory-vpn\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Syncing Active Directory Passwords Remotely: Two Common Problems\" \/>\n<meta property=\"og:description\" content=\"Learn how to sync a remote user\u2019s AD password, which usually requires a VPN, and how to sync VPN authentication to your central directory.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/jumpcloud.com\/blog\/sync-active-directory-vpn\" \/>\n<meta property=\"og:site_name\" content=\"JumpCloud\" \/>\n<meta property=\"article:published_time\" content=\"2021-05-25T15:00:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-11-14T22:19:37+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/jumpcloud.com\/wp-content\/uploads\/2019\/10\/sync-active-directory-vpn.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"780\" \/>\n\t<meta property=\"og:image:height\" content=\"507\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Sean Blanton\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Sean Blanton\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/jumpcloud.com\/blog\/sync-active-directory-vpn#article\",\"isPartOf\":{\"@id\":\"https:\/\/jumpcloud.com\/blog\/sync-active-directory-vpn\"},\"author\":{\"name\":\"Sean Blanton\",\"@id\":\"https:\/\/jumpcloud.com\/#\/schema\/person\/0c2a749d55fd9ade81d9f810c8d5aaa3\"},\"headline\":\"Syncing Active Directory Passwords Remotely: Two Common Problems\",\"datePublished\":\"2021-05-25T15:00:00+00:00\",\"dateModified\":\"2024-11-14T22:19:37+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/jumpcloud.com\/blog\/sync-active-directory-vpn\"},\"wordCount\":887,\"publisher\":{\"@id\":\"https:\/\/jumpcloud.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/jumpcloud.com\/blog\/sync-active-directory-vpn#primaryimage\"},\"thumbnailUrl\":\"https:\/\/jumpcloud.com\/wp-content\/uploads\/2019\/10\/sync-active-directory-vpn.jpg\",\"articleSection\":[\"How-To\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/jumpcloud.com\/blog\/sync-active-directory-vpn\",\"url\":\"https:\/\/jumpcloud.com\/blog\/sync-active-directory-vpn\",\"name\":\"Syncing AD Passwords Remotely: Two Common Problems - JumpCloud\",\"isPartOf\":{\"@id\":\"https:\/\/jumpcloud.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/jumpcloud.com\/blog\/sync-active-directory-vpn#primaryimage\"},\"image\":{\"@id\":\"https:\/\/jumpcloud.com\/blog\/sync-active-directory-vpn#primaryimage\"},\"thumbnailUrl\":\"https:\/\/jumpcloud.com\/wp-content\/uploads\/2019\/10\/sync-active-directory-vpn.jpg\",\"datePublished\":\"2021-05-25T15:00:00+00:00\",\"dateModified\":\"2024-11-14T22:19:37+00:00\",\"description\":\"Learn how to sync a remote user\u2019s AD password, which usually requires a VPN, and how to sync VPN authentication to your central directory.\",\"breadcrumb\":{\"@id\":\"https:\/\/jumpcloud.com\/blog\/sync-active-directory-vpn#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/jumpcloud.com\/blog\/sync-active-directory-vpn\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/jumpcloud.com\/blog\/sync-active-directory-vpn#primaryimage\",\"url\":\"https:\/\/jumpcloud.com\/wp-content\/uploads\/2019\/10\/sync-active-directory-vpn.jpg\",\"contentUrl\":\"https:\/\/jumpcloud.com\/wp-content\/uploads\/2019\/10\/sync-active-directory-vpn.jpg\",\"width\":780,\"height\":507,\"caption\":\"city scape and network connection concept\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/jumpcloud.com\/blog\/sync-active-directory-vpn#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/jumpcloud.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Syncing Active Directory Passwords Remotely: Two Common Problems\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/jumpcloud.com\/#website\",\"url\":\"https:\/\/jumpcloud.com\/\",\"name\":\"JumpCloud\",\"description\":\"Daily insights on directory services, IAM, LDAP, identity security, SSO, system management (Mac, Windows, Linux), networking, and the cloud.\",\"publisher\":{\"@id\":\"https:\/\/jumpcloud.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/jumpcloud.com\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/jumpcloud.com\/#organization\",\"name\":\"JumpCloud\",\"url\":\"https:\/\/jumpcloud.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/jumpcloud.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/jumpcloud.com\/wp-content\/uploads\/2021\/01\/jc-logo-brand-2021.png\",\"contentUrl\":\"https:\/\/jumpcloud.com\/wp-content\/uploads\/2021\/01\/jc-logo-brand-2021.png\",\"width\":598,\"height\":101,\"caption\":\"JumpCloud\"},\"image\":{\"@id\":\"https:\/\/jumpcloud.com\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/jumpcloud.com\/#\/schema\/person\/0c2a749d55fd9ade81d9f810c8d5aaa3\",\"name\":\"Sean Blanton\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/jumpcloud.com\/#\/schema\/person\/image\/0f493278829cf832b6cf8a58926a4585\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/596d142d20c23a1783684d7960968d4e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/596d142d20c23a1783684d7960968d4e?s=96&d=mm&r=g\",\"caption\":\"Sean Blanton\"},\"description\":\"Sean Blanton is the Director of Content at JumpCloud and has spent the past decade in the wide world of security, networking and IT and Infosec administration. When not at work Sean enjoys spending time with his young kids and geeking out on table top games.\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Syncing AD Passwords Remotely: Two Common Problems - JumpCloud","description":"Learn how to sync a remote user\u2019s AD password, which usually requires a VPN, and how to sync VPN authentication to your central directory.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/jumpcloud.com\/blog\/sync-active-directory-vpn","og_locale":"en_US","og_type":"article","og_title":"Syncing Active Directory Passwords Remotely: Two Common Problems","og_description":"Learn how to sync a remote user\u2019s AD password, which usually requires a VPN, and how to sync VPN authentication to your central directory.","og_url":"https:\/\/jumpcloud.com\/blog\/sync-active-directory-vpn","og_site_name":"JumpCloud","article_published_time":"2021-05-25T15:00:00+00:00","article_modified_time":"2024-11-14T22:19:37+00:00","og_image":[{"width":780,"height":507,"url":"https:\/\/jumpcloud.com\/wp-content\/uploads\/2019\/10\/sync-active-directory-vpn.jpg","type":"image\/jpeg"}],"author":"Sean Blanton","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Sean Blanton","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/jumpcloud.com\/blog\/sync-active-directory-vpn#article","isPartOf":{"@id":"https:\/\/jumpcloud.com\/blog\/sync-active-directory-vpn"},"author":{"name":"Sean Blanton","@id":"https:\/\/jumpcloud.com\/#\/schema\/person\/0c2a749d55fd9ade81d9f810c8d5aaa3"},"headline":"Syncing Active Directory Passwords Remotely: Two Common Problems","datePublished":"2021-05-25T15:00:00+00:00","dateModified":"2024-11-14T22:19:37+00:00","mainEntityOfPage":{"@id":"https:\/\/jumpcloud.com\/blog\/sync-active-directory-vpn"},"wordCount":887,"publisher":{"@id":"https:\/\/jumpcloud.com\/#organization"},"image":{"@id":"https:\/\/jumpcloud.com\/blog\/sync-active-directory-vpn#primaryimage"},"thumbnailUrl":"https:\/\/jumpcloud.com\/wp-content\/uploads\/2019\/10\/sync-active-directory-vpn.jpg","articleSection":["How-To"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/jumpcloud.com\/blog\/sync-active-directory-vpn","url":"https:\/\/jumpcloud.com\/blog\/sync-active-directory-vpn","name":"Syncing AD Passwords Remotely: Two Common Problems - JumpCloud","isPartOf":{"@id":"https:\/\/jumpcloud.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/jumpcloud.com\/blog\/sync-active-directory-vpn#primaryimage"},"image":{"@id":"https:\/\/jumpcloud.com\/blog\/sync-active-directory-vpn#primaryimage"},"thumbnailUrl":"https:\/\/jumpcloud.com\/wp-content\/uploads\/2019\/10\/sync-active-directory-vpn.jpg","datePublished":"2021-05-25T15:00:00+00:00","dateModified":"2024-11-14T22:19:37+00:00","description":"Learn how to sync a remote user\u2019s AD password, which usually requires a VPN, and how to sync VPN authentication to your central directory.","breadcrumb":{"@id":"https:\/\/jumpcloud.com\/blog\/sync-active-directory-vpn#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/jumpcloud.com\/blog\/sync-active-directory-vpn"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/jumpcloud.com\/blog\/sync-active-directory-vpn#primaryimage","url":"https:\/\/jumpcloud.com\/wp-content\/uploads\/2019\/10\/sync-active-directory-vpn.jpg","contentUrl":"https:\/\/jumpcloud.com\/wp-content\/uploads\/2019\/10\/sync-active-directory-vpn.jpg","width":780,"height":507,"caption":"city scape and network connection concept"},{"@type":"BreadcrumbList","@id":"https:\/\/jumpcloud.com\/blog\/sync-active-directory-vpn#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/jumpcloud.com\/"},{"@type":"ListItem","position":2,"name":"Syncing Active Directory Passwords Remotely: Two Common Problems"}]},{"@type":"WebSite","@id":"https:\/\/jumpcloud.com\/#website","url":"https:\/\/jumpcloud.com\/","name":"JumpCloud","description":"Daily insights on directory services, IAM, LDAP, identity security, SSO, system management (Mac, Windows, Linux), networking, and the cloud.","publisher":{"@id":"https:\/\/jumpcloud.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/jumpcloud.com\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/jumpcloud.com\/#organization","name":"JumpCloud","url":"https:\/\/jumpcloud.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/jumpcloud.com\/#\/schema\/logo\/image\/","url":"https:\/\/jumpcloud.com\/wp-content\/uploads\/2021\/01\/jc-logo-brand-2021.png","contentUrl":"https:\/\/jumpcloud.com\/wp-content\/uploads\/2021\/01\/jc-logo-brand-2021.png","width":598,"height":101,"caption":"JumpCloud"},"image":{"@id":"https:\/\/jumpcloud.com\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/jumpcloud.com\/#\/schema\/person\/0c2a749d55fd9ade81d9f810c8d5aaa3","name":"Sean Blanton","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/jumpcloud.com\/#\/schema\/person\/image\/0f493278829cf832b6cf8a58926a4585","url":"https:\/\/secure.gravatar.com\/avatar\/596d142d20c23a1783684d7960968d4e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/596d142d20c23a1783684d7960968d4e?s=96&d=mm&r=g","caption":"Sean Blanton"},"description":"Sean Blanton is the Director of Content at JumpCloud and has spent the past decade in the wide world of security, networking and IT and Infosec administration. When not at work Sean enjoys spending time with his young kids and geeking out on table top games."}]}},"_links":{"self":[{"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/posts\/34831"}],"collection":[{"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/users\/120"}],"replies":[{"embeddable":true,"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/comments?post=34831"}],"version-history":[{"count":2,"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/posts\/34831\/revisions"}],"predecessor-version":[{"id":117506,"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/posts\/34831\/revisions\/117506"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/media\/34833"}],"wp:attachment":[{"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/media?parent=34831"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/categories?post=34831"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/tags?post=34831"},{"taxonomy":"collection","embeddable":true,"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/collection?post=34831"},{"taxonomy":"platform","embeddable":true,"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/platform?post=34831"},{"taxonomy":"funnel_stage","embeddable":true,"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/funnel_stage?post=34831"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/coauthors?post=34831"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}