User accounts with “User must change password at next logon” are unable to log into Citrix XenApp or XenDesktop via the NetScaler portal

Problem

You’ve noticed that Active Directory user accounts with User must change password at next logon:

imageimage

… are unable to log into Citrix XenApp or XenDesktop via the NetScaler portal as the following error is presented:

Incorrect user name or password.

image

Solution

Two of the common reasons that could cause this behavior are as follows:

#1 – LDAP Servers are not configured with LDAPS

image

Note that the Security Type in the screenshot below is configured as SSL and the port is 636:

image

#2 – LDAP Servers does not have “Allow Password Change” enabled

Note the Allow Password Change option in the screenshot below that allows for password changes:

image

Once this option is enabled, the user will now be prompted with the following page to change their password:

image