Active Directory Password Policy
Description
A password policy that validates a password against different requirements. Those requirements are retrieved from the configured Active Directory connector. Validation can be done for different contexts, e.g. only on login or on password reset.
Note: This plugin does only check against certain requirements of the current password if this information is made available in the user data (e.g. latest-password-change-timestamp). Whether this is the case, may depend on the configuration of the underlying user persister.
May be used by
Password Reset Step Basic Auth Request Authentication Dynamic Active Directory String Generator Pattern-based Random String Generator Password-only Authentication Step Mandatory Password Change Step Administrators Configuration Username Password Authentication Step Voluntary Password Change Step Password Change Self-Service Step Password Settings Username Password with FIDO Authentication Step Set Password Step HTTP Basic Authentication Step Password User Item
Properties
Active Directory Connector (
activeDirectoryConnector) Description
Provides access to the schema of an Active Directory to retrieve the current password policy for certain users.
Attributes
Plugin-Link
Mandatory
Assignable plugins
YAML Template (with default values)
type: ActiveDirectoryPasswordPolicy
id: ActiveDirectoryPasswordPolicy-xxxxxx
displayName:
comment:
properties:
activeDirectoryConnector: