Re: ADAM custom password policy

Tech-Archive recommends: Fix windows errors by optimizing your registry



Hi

ADAM specific password policies have been asked for a number
of times. Hopefully Microsoft will pick up the idea. One thing you
could try is setting a password policy at the OU level in a domain
environment and placing your ADAM servers in that OU (I have yet
to try this out).

When you say "additional actions (e.g. auditing)" what do you have in
mind here? If you have logon auditing enabled in your server audit policy
you should see ADAM user logon audit events, for windows principals
you should see a logon event in the local server or DC depending on
the account.

Thanks
Lee Flight

"roberto" <roberto.marchickos@xxxxxxxxx> wrote in message
news:1153814118.447482.60950@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Is it possible to make ADAM to call a configurable "plugin" to enforce
custom policy?
As I understand you can disable default policy enforcement (which calls
OS API NetValidateUserPassword) - so may be you can also refirect this
call somehow?

It would be nice to apply extended (comparing to OS) password policies
to users authenticating using standard LDAP; also, the "plugin" could
perform additional actions (e.g. auditing). And all of this using
secure and extensible AD store...

Any thoughts on this?



.



Relevant Pages

  • Re: ADAm password policies
    ... Thanks to you & Lee. ... password policies ... This difference means I might have to write that policy into the ... My sense so far in working with ADAM is that MS has not divorced it well ...
    (microsoft.public.windows.server.active_directory)
  • Re: ADAM Password Policies
    ... On means use the password policy on the machine on which adam is hosted. ... > instance there is no way to configure instance-specific password policies. ... >>> I would like a particular ADAM instance to use its own password ...
    (microsoft.public.windows.server.active_directory)
  • Re: ADAM and Password Policies
    ... Modifications to password policies only apply to future password changes. ... otherwise expire under your policy. ... ADAM actually inherits the password policy applied to the machine that ADAM ... as it is pretty difficult to provide a clean mechanism to allow ADAM users ...
    (microsoft.public.windows.server.active_directory)
  • Re: password policy not working
    ... Password Policies within a GPO only applies to local accounts for the ... Do define such settings for Domain Users, ... I have assigned a group policy to test and am ... > server to force pw change at next logon, ...
    (microsoft.public.windows.server.active_directory)
  • Re: ADAm password policies
    ... There was never a plan to divorce ADAM from OS, 95% of ADAM is pure AD, and ... If you need to institute a different pwd policy for ADAM users, ... > password policies ...
    (microsoft.public.windows.server.active_directory)