Credential Sync Latency and Password Change Enforcement on Entra-Joined Devices via AD FS

Atat Redihan 0 แต้มความนิยม
2026-05-06T08:31:02.8566667+00:00

In an enterprise environment utilizing a federated identity model, we are observing a discrepancy in credential validation for cloud-tethered workstations. After an administrative reset in the local directory where the "force password change" flag is toggled, a remote user on an Entra-joined device finds that the Windows login interface rejects the new temporary credentials as invalid. Interestingly, the workstation continues to grant access only via the expired cached credentials, effectively bypassing the mandatory change requirement. Does this cached credential behavior on an Entra-joined machine represent the standard operational design for federated accounts, or should the local security authority be enforcing the backend password policy immediately?

Windows สำหรับธุรกิจ | Windows 365 Enterprise
0 ความคิดเห็น ไม่มีข้อคิดเห็น

1 คำตอบ

เรียงลำดับตาม: มีประโยชน์มากที่สุด
  1. Tracy Le 13,210 แต้มความนิยม ที่ปรึกษาอิสระ
    2026-05-06T10:16:25.7633333+00:00

    Hi Atat Redihan,

    To answer your question directly: Yes, this is the standard and expected operational design for remote Entra-joined devices. It is not a bug.

    Here is the technical reality of why this happens and how you handle it in a federated environment:

    1. The Cached Credential Bypass: An off-network Entra-joined workstation does not have a line-of-sight to your on-prem Domain Controllers. It authenticates against the local LSA cache and its Primary Refresh Token (PRT). Because it cannot reach the local directory, the machine has no immediate awareness of the "force password change" flag. The old cached password will continue to unlock the machine until the PRT expires or is forcibly revoked.

    2. The Temporary Password Rejection: The standard Windows logon credential provider cannot natively process an AD FS "User must change password at next logon" prompt when the device is off-network. When the user enters the temporary password, Windows simply sees an invalid credential/PRT mismatch and rejects it.

    The Enterprise Solutions:

    The Web-First Approach (Fastest workaround): Instruct the remote user to log into portal.office.com via a mobile device or web browser first. This will trigger the proper AD FS password change flow. Once they set a new permanent password, they can connect their laptop to the internet and log in with the new permanent password.

    Enable Web Sign-in (Long-term fix): Use Intune to enable the Web Sign-in credential provider for Windows. This forces the lock screen to render the actual Entra ID / AD FS web authentication page, allowing the remote user to process the "force password change" flow directly at the Windows login screen.

    Immediate Enforcement: If security requires the cached credentials to stop working immediately, an Administrator must go to the Entra ID portal and click "Revoke Sessions" for that user. This invalidates the PRT and forces a fresh authentication.

    If this clarifies the mechanics of your federated identity architecture, please click "Accept Answer".

    Tracy Le.

    คำตอบนี้มีประโยชน์หรือไม่

    1 คนพบว่าคำตอบนี้มีประโยชน์
    0 ความคิดเห็น ไม่มีข้อคิดเห็น

คำตอบของคุณ

คำตอบสามารถทำเครื่องหมายว่า “ยอมรับ” โดยผู้เขียนคำถาม และ “แนะนำ” โดยผู้ดูแลระบบ ซึ่งจะช่วยให้ผู้ใช้ทราบว่าคำตอบนั้นแก้ไขปัญหาของผู้เขียนได้