
This will allow users to change their password any time without waiting till it expires. You can add a link to the password change form directly to the Remote Desktop WebAccess sign-in form. Adding Password Change Link to the RD Web Access Login Form
#2012 r2 remote desktop services password expired update
You can change an expired password on Windows Server 2008 R2 with the RD Web Access Role after installing the special update KB2648402. To change the password, the user must authenticate via the RDS-WebAccess sign-in web-page and change the password using a special aspx form. In Windows 2012 R2 and newer, remote users can manually reset their password (current password or expired password) through a special web page on the server with the Remote Desktop Web Access role. Certainly, you can ask your users to change their passwords directly in the RDP session in advance, or by enabling the Interactive logon: Prompt user to change password before expiration GPO option RDS hosts (Computer Configuration -> Windows Settings -> Local Policies -> Security Options), but it doesn’t always work due to a common forgetfulness of the users. When using NLA, remote RDP users cannot change their expired password if they have no other way to access the corporate network other than RDS infrastructure.

Please update your password if it has expired. The Local Security Authority cannot be contacted When you try to connect to the RDSH server (Remote Desktop Session Host) under a user account with the expired password, the following error message appears: An authentication error has occurred. You can disable NLA ( ref1, ref2), but this is not good in terms of security. NLA prevents users from connecting to RDP/RDS hosts if their passwords have expired or who have the “ User must change password at first Logon” option enabled in their useraccountcontrol user attribute.

In Windows Server 2012 R2 and newer, the NLA (Network Level Authentication) is enabled for the Remote Desktop connections by default. Can’t Change Expired Password from a Remote Desktop Session
