Active Directory Password Policy Connector
Description
This plugin retrieves a Password Policy Object (PSO) for a specific user from an Active Directory (AD) via the configured LDAP connection.
May be used by
Properties
Connection Pool (
connectionPool) Description
The settings used to talk to the LDAP directory (or active directory).
Attributes
Plugin-Link
Mandatory
Assignable plugins
Domain DN (
domainDN) Description
The distinguished name (DN) of the domain the active directory schema.
Attributes
String
Mandatory
Example
dc=example, dc=org
Password Settings Container DN (
passwordSettingsContainerDN) Description
The distinguished name (DN) of the Password Settings Container (PSC) in the active directory schema.
Attributes
String
Mandatory
Example
cn=Password Settings Container, cn=System, dc=example, dc=org
Username Attribute (
userIdAttributeName) Description
The name of the attribute that holds the user id.
Attributes
String
Optional
Default value
sAMAccountName
Suggested values
cn, sAMAccountName, userPrincipalName
User Search Bases (
searchBases) Description
Defines a list of search contexts (search trees with search levels) to use when looking for users. The search contexts are used in the defined order. If left unconfigured sensible defaults apply.
Attributes
String-List
Optional
User Search Scope (
searchScope) Description
Specifies whether the search should also recurse down the subtrees of the search base nodes or only the direct children nodes of the search base nodes should be searched.
Valid values are SUB and ONE.
Attributes
Enum
Optional
Default value
SUBTREE
User Search Filter (
searchFilter) Description
The additional LDAP search filter expression used when searching the user to check the password for. This filter is automatically combined (by a logical and) with a username filter based on the Username Attribute name.
The format and interpretation of filter follows RFC 2254.
Attributes
String
Optional
Multi-line-text
Default value
(objectClass=person)
Example
(objectClass=person)
LDS Mode (
adLdsMode) Description
Activates the AD LDS mode of operation ("Lightweight Directory Services")
Attributes
Boolean
Optional
Default value
false
YAML Template (with default values)
type: ActiveDirectoryPasswordPolicyConnector
id: ActiveDirectoryPasswordPolicyConnector-xxxxxx
displayName:
comment:
properties:
adLdsMode: false
connectionPool:
domainDN:
passwordSettingsContainerDN:
searchBases:
searchFilter: (objectClass=person)
searchScope: SUBTREE
userIdAttributeName: sAMAccountName